【24h】

Locality-Based Security Policies

机译:基于地方的安全策略

获取原文

摘要

Information flow security provides a strong notion of end-to-end security in computing systems. However sometimes the policies for information flow security are limited in their expressive power, hence complicating the matter of specifying policies even for simple systems. These limitations often become apparent in contexts where confidential information is released under specific conditions. We present a novel policy language for expressing permissible information flow under expressive constraints on the execution traces for programs. Based on the policy language we propose a security condition shown to be a generalized intransitive non-interference condition. Furthermore a flow-logic based static analysis is presented and shown capable of guaranteeing the security of programs analysed.
机译:信息流安全性提供了在计算系统中的最终安全性的强大概念。然而,有时,信息流安全的政策在其表现力的力量中受到限制,因此即使对于简单的系统而言,即使为简单的系统指定策略的问题也会复杂化。在机密信息在特定条件下释放的背景下,这些限制通常变得显而易见。我们提出了一种新的策略语言,用于表达允许的信息流在执行跟踪的表达约束下进行程序。基于策略语言,我们提出了一种安全条件,显示为广义不动的非干扰条件。此外,提供了一种基于流逻辑的静态分析,并显示了能够保证分析程序的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号