...
首页> 外文期刊>Journal of computer security >Iterative enforcement by suppression: Towards practical enforcement theories
【24h】

Iterative enforcement by suppression: Towards practical enforcement theories

机译:通过压制进行反复执法:迈向实用执法理论

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Runtime enforcement is a common mechanism for ensuring that program executions adhere to constraints specifie by a security policy. It is based on two simple ideas: the enforcement mechanism should leave good executions without changes (transparency) and make sure that the bad ones got amended (soundness). From the theory side, a number of papers (Hamlen et al., Ligatti et al., Talhi et al.) provide the precise characterization of good executions that can be captured by a security policy and thus enforced by mechanisms like security automata or edit automata. Unfortunately, transparency and soundness do not distinguish what happens when an execution is actually bad (the practical case). They only tell that the outcome of enforcement mechanism should be "good" but not how far the bad execution should be changed. So we cannot formally distinguish between an enforcement mechanism that makes a small change and one that drops the whole execution. In this paper we explore a set of policies called iterative properties that revises the notion of good executions in terms of repeated iterations. We propose an enforcement mechanism that can deal with bad executions (and not only the good ones) in a more predictable way by eliminating bad iterations.
机译:运行时强制执行是一种通用机制,可确保程序执行遵守安全策略指定的约束。它基于两个简单的思想:强制执行机制应使良好的执行保持不变(透明度),并确保对不良的执行进行修正(健全)。从理论的角度来看,许多论文(Hamlen等人,Ligatti等人,Talhi等人)提供了可以由安全策略捕获并因此由安全性自动机或编辑等机制强制执行的良好执行的精确特征。自动机。不幸的是,透明性和健全性并不能区分当执行实际上很糟糕时(实际情况)会发生什么。他们只说执行机制的结果应该是“好的”,而不是应该改变不良执行的程度。因此,我们无法在形式上区分执行微小更改的执行机制和丢弃整个执行的执行机制。在本文中,我们探索了一组称为迭代属性的策略,该策略根据重复迭代来修改良好执行的概念。我们提出了一种强制机制,该机制可以通过消除错误的迭代来以更可预测的方式处理错误的执行(而不仅仅是良好的执行)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号