...
首页> 外文期刊>International Journal of Information Security >Edit automata: enforcement mechanisms for run-time security policies
【24h】

Edit automata: enforcement mechanisms for run-time security policies

机译:编辑自动机:运行时安全策略的强制机制

获取原文
获取原文并翻译 | 示例

摘要

We analyze the space of security policies that can be enforced by monitoring and modifying programs at run time. Our program monitors, called edit automata, are abstract machines that examine the sequence of application program actions and transform the sequence when it deviates from a specified policy. Edit automata have a rich set of transformational powers: they may terminate an application, thereby truncating the program action stream; they may suppress undesired or dangerous actions without necessarily terminating the program; and they may also insert additional actions into the event stream. After providing a formal definition of edit automata, we develop a rigorous framework for reasoning about them and their cousins: truncation automata (which can only terminate applications), suppression automata (which can terminate applications and suppress individual actions), and insertion automata (which can terminate and insert). We give a set-theoretic characterization of the policies each sort of automaton can enforce, and we provide examples of policies that can be enforced by one sort of automaton but not another.
机译:我们分析了可以通过在运行时监视和修改程序来实施的安全策略的空间。我们的程序监控器称为“编辑自动机”,是抽象机,用于检查应用程序动作的顺序,并在其偏离指定策略时对其进行转换。编辑自动机具有丰富的转换能力:它们可以终止应用程序,从而截断程序操作流;他们可能会压制不良或危险的行为,而不必终止程序;并且他们还可能在事件流中插入其他操作。在提供编辑自动机的正式定义之后,我们开发了一个严格的框架来推理它们及其表亲:截断自动机(只能终止应用程序),抑制自动机(可以终止应用程序并抑制单个动作)和插入自动机(其中可以终止并插入)。我们对每种自动机可以执行的策略进行了集理论上的描述,并提供了可以由一种自动机执行但不能由另一种自动机执行的策略示例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号