This invention discloses a method and
system for automated policy deduction based on descriptive logic, comprising: creating a structured policy; storing the structured policy as an
XACML format policy; translating the
XACML format policy into a formal policy; converting the formal policy into a concrete policy according to the policy objective interpretation environment to be implemented; instantiating the concrete policy, generating instances of policy objects, and distributing them to actual devices for execution. This invention, through formal
security policy expression, utilizes a policy center to achieve automated deduction, decision-making, and execution of security policies, effectively reducing the difficulty of policy management for administrators and improving
security management efficiency.