Prudent Design Principles for Information Flow Control

被引:4
|
作者
Bastys, Iulia [1 ]
Piessens, Frank [2 ]
Sabelfeld, Andrei [1 ]
机构
[1] Chalmers Univ Technol, Gothenburg, Sweden
[2] Katholieke Univ Leuven, Heverlee, Belgium
基金
瑞典研究理事会;
关键词
information flow control; attacker models; principles; IMPLICIT FLOWS; DECLASSIFICATION; NONINTERFERENCE; SECURITY;
D O I
10.1145/3264820.3264824
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Recent years have seen a proliferation of research on information flow control. While the progress has been tremendous, it has also given birth to a bewildering breed of concepts, policies, conditions, and enforcement mechanisms. Thus, when designing information flow controls for a new application domain, the designer is confronted with two basic questions: (i) What is the right security characterization for a new application domain? and (ii) What is the right enforcement mechanism for a new application domain? This paper puts forward six informal principles for designing information flow security definitions and enforcement mechanisms: attacker-driven security, trust-aware enforcement, separation of policy annotations and code, language-independence, justified abstraction, and permissiveness. We particularly highlight the core principles of attacker-driven security and trust-aware enforcement, giving us a rationale for deliberating over soundness vs. soundiness. The principles contribute to roadmapping the state of the art in information flow security, weeding out inconsistencies from the folklore, and providing a rationale for designing information flow characterizations and enforcement mechanisms for new application domains.
引用
收藏
页码:17 / 23
页数:7
相关论文
共 50 条
  • [11] On applying information principles to fuzzy control
    Padet, C
    [J]. KYBERNETES, 1996, 25 (01) : 61 - &
  • [12] PRINCIPLES OF DESIGN AND APPRAISAL OF STATISTICAL INFORMATION SYSTEMS
    ROSENBLA.D
    GLASER, E
    WOOD, MK
    [J]. AMERICAN STATISTICIAN, 1970, 24 (04): : 10 - &
  • [13] Streamlining an interface using information design principles
    Hart, G
    [J]. STC'S 50TH ANNUAL CONFERENCE, PROCEEDINGS, 2003, : 378 - 381
  • [14] Basic Principles of Information System UI Design
    Yin, Ruijie
    Zhang, Bingjun
    Kang, Meng
    Li, Tao
    Chen, Kang
    Kang, Yong
    [J]. PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON MAN-MACHINE-ENVIRONMENT SYSTEM ENGINEERING, 2015, 356 : 419 - 423
  • [15] INTRODUCING INFORMATION DESIGN PRINCIPLES AND PRACTICES TO GRAPHIC DESIGN STUDENTS
    Hartmann, Kay
    [J]. 4TH INTERNATIONAL TECHNOLOGY, EDUCATION AND DEVELOPMENT CONFERENCE (INTED 2010), 2010, : 3455 - 3461
  • [16] Quantifying Information Transfer Through a Head-Attached Vibrotactile Display: Principles for Design and Control
    Dobrzynski, Michal Karol
    Mejri, Seifeddine
    Wischmann, Steffen
    Floreano, Dario
    [J]. IEEE TRANSACTIONS ON BIOMEDICAL ENGINEERING, 2012, 59 (07) : 2011 - 2018
  • [17] DESIGN PRINCIPLES OF A SYSTEM FOR THE ACCESS-CONTROL TO INFORMATION-SYSTEMS IN COMPUTER-NETWORKS
    ZINOVJEV, EV
    BRIKMAN, GA
    [J]. AVTOMATIKA I VYCHISLITELNAYA TEKHNIKA, 1984, (02): : 3 - 10
  • [18] Towards using possibilistic information flow control to design secure multiagent systems
    Schairer, A
    [J]. SECURITY IN PERVASIVE COMPUTING, 2004, 2802 : 101 - 115
  • [19] Secure Hardware Design Through Bit-tight Information Flow Control
    Mao Baolei
    Hu Wei
    Tai Yu
    Zhang Huixiang
    Mu Dejun
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE OF IEEE REGION 10 (TENCON), 2013,
  • [20] CONTROL AND DESIGN PRINCIPLES IN BIOLOGICAL MINERALIZATION
    ADDADI, L
    WEINER, S
    [J]. ANGEWANDTE CHEMIE-INTERNATIONAL EDITION, 1992, 31 (02) : 153 - 169