...
首页> 外文期刊>Journal of software >Flow-Sensitive Automaton-Based Monitoring of a Declassification Policy
【24h】

Flow-Sensitive Automaton-Based Monitoring of a Declassification Policy

机译:基于流量敏感自动机的解密策略监控

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Declassification policies aim to guarantee trustedrelease of confidential information. The semantic securityconditions of declassification policies focus on differentdimensions. In order to prevent the special attacks aiming tocompromise the mechanisms of declassification, it isimportant for a declassification policy to combine differentdimensions. Moreover, current body of work on theenforcement of the declassification policy focuses on staticand flow-insensitive information-flow analysis, which isover-restrictive and imprecise. Dynamic and flow-sensitiveinformation flow analysis techniques offer distinctadvantages in permissiveness and precision. As a step inthese directions, this paper first presents a declassificationpolicy combining two dimensions, which control the amountand the location of confidential information releaserespectively, based on the security-typed language proposed.Then we presents an automaton-based monitoringmechanisms of the declassification policy. Abstractions ofevents occurring during the execution of a program are sentto the automaton as inputs, and the automaton uses theseinputs to track the information flows and controls theexecution of the program by forbidding or editing insecurecommands that violate the declassification policy.Additionally, we prove the monitoring mechanism proposedis sound.
机译:解密策略旨在确保机密信息的可信发布。解密策略的语义安全条件侧重于不同维度。为了防止旨在破坏解密机制的特殊攻击,将不同维度组合在一起的解密策略非常重要。此外,当前执行解密政策的工作重点是静态和对流量不敏感的信息流分析,这种分析过于严格且不够精确。动态和对流量敏感的信息流分析技术在宽松性和精确性方面具有明显的优势。作为朝着这些方向迈出的一步,本文首先基于提出的安全类型语言提出了一种结合两个维度的解密策略,该策略分别控制机密信息的发布数量和位置。然后,我们提出了一种基于自动机的解密策略监控机制。在程序执行期间发生的事件的抽象作为输入发送到自动机,并且自动机使用这些输入来跟踪信息流并通过禁止或编辑违反解密策略的不安全命令来控制程序的执行。此外,我们证明了监视机制建议的声音。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号