首页> 外文期刊>ACM Transaction on Information and System Security >Corrective Enforcement: A New Paradigm of Security Policy Enforcement by Monitors
【24h】

Corrective Enforcement: A New Paradigm of Security Policy Enforcement by Monitors

机译:纠正性执行:监视器执行安全策略的新范式

获取原文
获取原文并翻译 | 示例

摘要

Runtime monitoring is an increasingly popular method to ensure the safe execution of untrusted codes. Monitors observe and transform the execution of these codes, responding when needed to correct or prevent a violation of a user-defined security policy. Prior research has shown that the set of properties monitors can enforce correlates with the latitude they are given to transform and alter the target execution. But for enforcement to be meaningful this capacity must be constrained, otherwise the monitor can enforce any property, but not necessarily in a manner that is useful or desirable. However, such constraints have not been significantly addressed in prior work. In this article, we develop a new paradigm of security policy enforcement in which the behavior of the enforcement mechanism is restricted to ensure that valid aspects present in the execution are preserved notwithstanding any transformation it may perform. These restrictions capture the desired behavior of valid executions of the program, and are stated by way of a preorder over sequences. The resulting model is closer than previous ones to what would be expected of a real-life monitor, from which we demand a minimal footprint on both valid and invalid executions. We illustrate this framework with examples of real-life security properties. Since several different enforcement alternatives of the same property are made possible by the flexibility of this type of enforcement, our study also provides metrics that allow the user to compare monitors objectively and choose the best enforcement paradigm for a given situation.
机译:运行时监视是确保安全执行不受信任的代码的一种越来越流行的方法。监视器观察并转换这些代码的执行,并在需要时做出响应,以更正或防止违反用户定义的安全策略。先前的研究表明,属性监视器的集合可以与它们赋予的纬度强制相关,以转换和更改目标执行。但是,为了使执行有意义,必须限制此功能,否则监视器可以强制执行任何属性,但不一定以有用或期望的方式执行。但是,这些限制在先前的工作中并未得到明显解决。在本文中,我们开发了一种新的安全策略执行范式,其中对执行机制的行为进行了限制,以确保执行中存在的有效方面得以保留,即使它可以执行任何转换。这些限制捕获了程序有效执行的期望行为,并通过对序列的预购来说明。最终的模型比以前的模型更接近于实际监视器的期望值,从中我们需要在有效和无效执行上都具有最小的占用空间。我们以现实生活中的安全属性为例来说明此框架。由于这种类型的强制执行的灵活性使相同属性的几种不同的强制执行选择成为可能,因此我们的研究还提供了一些指标,允许用户客观地比较监视器并针对给定情况选择最佳的执行范例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号