@techreport{TR-IC-06-05, number = {IC-06-05}, author = {João Porto de Albuquerque}, title = {Scalable Model-based Policy Refinement and Validation for Network Security Systems}, month = {March}, year = {2006}, institution = {Institute of Computing, University of Campinas}, note = {In English, 58 pages. \par\selectlanguage{english}\textbf{Abstract} This report builds upon previous work on Model-based Management, and particularly on the Diagram of Abstract Subsystems (DAS) approach, further elaborating on the correctness and performance of the automated policy refinement process. The modelling technique and the automated policy refinement process are firstly presented to illustrate the practical use of the DAS approach. Subsequently, the graphical model is formalised using an algebraic notation, which is thus utilised to define validation conditions for a layered model, i.e. conditions to which a resulting model must comply if the lower-level policy sets have been correctly generated. The scalability of the refinement algorithms and the additional effort needed to validate model instances are also analysed and discussed. } }