...
首页> 外文期刊>Journal of software >Flow-Sensitive Automaton-Based Monitoring of a Declassification Policy
【24h】

Flow-Sensitive Automaton-Based Monitoring of a Declassification Policy

机译:基于流量敏感自动机的解密策略监控

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Declassification policies aim to guarantee trusted release of confidential information. The semantic security conditions of declassification policies focus on different dimensions. In order to prevent the special attacks aiming to compromise the mechanisms of declassification, it is important for a declassification policy to combine different dimensions. Moreover, current body of work on the enforcement of the declassification policy focuses on static and flow-insensitive information-flow analysis, which is over-restrictive and imprecise. Dynamic and flow-sensitive information flow analysis techniques offer distinct advantages in permissiveness and precision. As a step in these directions, this paper first presents a declassification policy combining two dimensions, which control the amount and the location of confidential information release respectively, based on the security-typed language proposed. Then we presents an automaton-based monitoring mechanisms of the declassification policy. Abstractions of events occurring during the execution of a program are sent to the automaton as inputs, and the automaton uses these inputs to track the information flows and controls the execution of the program by forbidding or editing insecure commands that violate the declassification policy. Additionally, we prove the monitoring mechanism proposed is sound.
机译:解密策略旨在确保机密信息的可信发布。解密策略的语义安全条件集中在不同的维度上。为了防止旨在破坏解密机制的特殊攻击,对于解密策略而言,重要的是要结合不同的维度。而且,当前执行解密策略的工作集中在静态和对流量不敏感的信息流分析上,这种分析过于严格和不精确。动态和对流量敏感的信息流分析技术在宽松性和精确性方面具有明显的优势。作为朝着这些方向迈出的一步,本文首先提出了一种结合两个维度的解密策略,该策略基于提出的安全类型语言分别控制机密信息发布的数量和位置。然后,我们提出了基于自动机的解密策略监控机制。在程序执行期间发生的事件的抽象将作为输入发送到自动机,并且自动机使用这些输入来跟踪信息流,并通过禁止或编辑违反解密策略的不安全命令来控制程序的执行。此外,我们证明提出的监控机制是合理的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号