首页> 外文会议>2012 IEEE 25th computer security foundations symposium >Learning is Change in Knowledge: Knowledge-Based Security for Dynamic Policies
【24h】

Learning is Change in Knowledge: Knowledge-Based Security for Dynamic Policies

机译:学习就是知识的变化:动态策略的基于知识的安全性

获取原文
获取原文并翻译 | 示例

摘要

In systems that handle confidential information, the security policy to enforce on information frequently changes: new users join the system, old users leave, and sensitivity of data changes over time. It is challenging, yet important, to specify what it means for such systems to be secure, and to gain assurance that a system is secure. We present a language-based model for specifying, reasoning about, and enforcing information security in systems that dynamically change the security policy. We specify security for such systems as a simple and intuitive extensional knowledge-based semantic condition: an attacker can only learn information in accordance with the current security policy. Importantly, the semantic condition is parameterized by the ability of the attacker. Learning is about change in knowledge, and an observation that allows one attacker to learn confidential information may provide a different attacker with no new information. A program that is secure against an attacker with perfect recall may not be secure against a more realistic, weaker, attacker. We introduce a compositional model of attackers that simplifies enforcement of security, and demonstrate that standard information-flow control mechanisms, such as security-type systems and information-flow monitors, can be easily adapted to enforce security for a broad and useful class of attackers.
机译:在处理机密信息的系统中,要对信息强制执行的安全策略会经常更改:新用户加入系统,旧用户离开系统,以及数据随时间变化的敏感性。明确说明此类系统安全意味着什么并确保系统安全是具有挑战性但很重要的。我们提出了一种基于语言的模型,用于在动态更改安全策略的系统中指定,推理和实施信息安全。我们将此类系统的安全性指定为一种简单而直观的基于知识的扩展性语义条件:攻击者只能根据当前的安全策略来学习信息。重要的是,语义条件是由攻击者的能力参数化的。学习是关于知识的变化,而允许一个攻击者学习机密信息的观察结果可能会为其他攻击者提供新的信息。一个针对攻击者的安全且具有完美召回性的程序可能对较现实的,较弱的攻击者而言不是安全的。我们介绍了一种简化了安全性实施的攻击者组成模型,并演示了标准信息流控制机制(例如安全类型系统和信息流监视器)可以轻松地适用于为广泛且有用的攻击者类别实施安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号