Prudent Design Principles for Information Flow Control

被引:4
|
作者
Bastys, Iulia [1 ]
Piessens, Frank [2 ]
Sabelfeld, Andrei [1 ]
机构
[1] Chalmers Univ Technol, Gothenburg, Sweden
[2] Katholieke Univ Leuven, Heverlee, Belgium
基金
瑞典研究理事会;
关键词
information flow control; attacker models; principles; IMPLICIT FLOWS; DECLASSIFICATION; NONINTERFERENCE; SECURITY;
D O I
10.1145/3264820.3264824
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Recent years have seen a proliferation of research on information flow control. While the progress has been tremendous, it has also given birth to a bewildering breed of concepts, policies, conditions, and enforcement mechanisms. Thus, when designing information flow controls for a new application domain, the designer is confronted with two basic questions: (i) What is the right security characterization for a new application domain? and (ii) What is the right enforcement mechanism for a new application domain? This paper puts forward six informal principles for designing information flow security definitions and enforcement mechanisms: attacker-driven security, trust-aware enforcement, separation of policy annotations and code, language-independence, justified abstraction, and permissiveness. We particularly highlight the core principles of attacker-driven security and trust-aware enforcement, giving us a rationale for deliberating over soundness vs. soundiness. The principles contribute to roadmapping the state of the art in information flow security, weeding out inconsistencies from the folklore, and providing a rationale for designing information flow characterizations and enforcement mechanisms for new application domains.
引用
收藏
页码:17 / 23
页数:7
相关论文
共 50 条
  • [1] Prudent design principles for digital tampering experiments
    Schneider, Janine
    Duesel, Linus
    Lorch, Benedikt
    Drafz, Julia
    Freiling, Felix
    [J]. FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2022, 40
  • [2] DESIGN OF INFORMATION-FLOW FOR PRODUCTION CONTROL
    BENDEICH, E
    LANG, F
    [J]. WERKSTATTSTECHNIK ZEITSCHRIFT FUR INDUSTRIELLE FERTIGUNG, 1974, 64 (11): : 682 - 686
  • [3] Vectors of information flow between biology and microelectronics: Design principles and enabling technologies
    Bentley, William
    [J]. ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2019, 257
  • [4] Nickel: A Framework for Design and Verification of Information Flow Control Systems
    Sigurbjarnarson, Helgi
    Nelson, Luke
    Castro-Karney, Bruno
    Bornholt, James
    Torlak, Emina
    Wang, Xi
    [J]. PROCEEDINGS OF THE 13TH USENIX SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION, 2018, : 287 - 305
  • [5] Principles of secure information flow analysis
    Smith, Geoffrey
    [J]. Malware Detection, 2007, : 291 - 307
  • [6] Prudent Health and Care: from principles to practice
    Howson, Helen
    [J]. INTERNATIONAL JOURNAL OF INTEGRATED CARE, 2021, 20
  • [7] 'Global principles' for prudent use of antibiotics in animals
    不详
    [J]. VETERINARY RECORD, 1999, 144 (10) : 246 - 246
  • [8] Design principles for environmental information systems
    Swayne, DA
    [J]. ENVIRONMENTAL MODELLING & SOFTWARE, 2001, 16 (05) : 417 - 417
  • [9] First principles in information visualization design
    Czerwinski, M
    [J]. FIFTH INTERNATIONAL CONFERENCE ON INFORMATION VISUALISATION, PROCEEDINGS, 2001, : 285 - 286
  • [10] PRINCIPLES OF DESIGN FOR INFORMATION-SYSTEMS
    ZIMMERMAN, PJ
    [J]. JOURNAL OF THE AMERICAN SOCIETY FOR INFORMATION SCIENCE, 1977, 28 (04): : 183 - 191