SPNDL: Security Policy Notation and Description Language
How can you specify security policies so that computers can analyze and enforce them? SPNDL began as an eccentric idea for building a policy domain-specific language (DSL), and evolved into one of the most in-depth research projects I've ever undertaken. Before its conclusion, the effort yielded not only syntax and semantics required to formally (and unambiguously) specify system-level security policies, but also an entire family of programs for working with them.
This talk will begin by introducing SPNDL, the Security Policy Notation and Description Language. The presentation will detail the goals leading to SPNDL's inception and development, while also providing a theory of operation. It will feature real examples of SPNDL policies as well as delve into the architecture of its surrounding toolset. After detailing pros and cons, this talk will conclude with a brief enumeration of future work opportunities.