首页> 外文会议>International Conference on Secure IT Systems >Generating In-Line Monitors for Rabin Automata
【24h】

Generating In-Line Monitors for Rabin Automata

机译:为Rabin Automata生成在线监视器

获取原文

摘要

A promising solution to the problem of securing potentially malicious mobile code lies in the use of program monitors. Such monitors can be in-lined into an untrusted program to produce an instrumented code that provably satisfies the security policy. It is well known that enforcement mechanisms based on Schneider's security automata only enforce safety properties [1]. Yet subsequent studies show that a wider range of properties than those implemented so far could be enforced using monitors. In this paper, we present an approach to produce a model of an instrumented program from a security requirement represented by a Rabin automaton and a model of the program. Based on an a priori knowledge of the program behavior, this approach allows to enforce, in some cases, more than safety properties. We provide a theorem stating that a truncation enforcement mechanism considering only the set of possible executions of a specific program is strictly more powerful than a mechanism considering all the executions over an alphabet of actions.
机译:对保护潜在恶意移动代码的问题的有希望的解决方案在于使用程序监视器。此类监视器可以内衬到不受信任的程序中,以产生可提供仪器的代码,可提供安全策略。众所周知,基于Schneider的安全自动机的执法机制仅执行安全性质[1]。然而,随后的研究表明,可以使用监视器强制执行比到目前为止所实施的那些更广泛的性质。在本文中,我们提出了一种从Rabin Automaton和程序模型代表的安全要求中生成仪表计划模型的方法。基于对程序行为的先验知识,此方法允许在某些情况下强制执行,而不是安全性。我们提供了一个定理,说明截断执法机制考虑只考虑特定程序的可能执行的一组可能比考虑所有执行所有执行的机制更强大。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号