Secure information flow as a safety problem

被引:0
|
作者
Terauchi, T
Aiken, A
机构
[1] Univ Calif Berkeley, EECS Dept, Berkeley, CA 94720 USA
[2] Stanford Univ, Comp Sci Dept, Stanford, CA USA
来源
STATIC ANALYSIS, PROCEEDINGS | 2005年 / 3672卷
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The termination insensitive secure information flow problem can be reduced to solving a safety problem via a simple program transformation. Barthe, D'Argenio, and Rezk coined the term "self-composition" to describe this reduction. This paper generalizes the self-compositional approach with a form of information downgrading recently proposed by Li and Zdancewic. We also identify a problem with applying the self-compositional approach in practice, and we present a solution to this problem that makes use of more traditional type-based approaches. The result is a framework that combines the best of both worlds, i.e., better than traditional type-based approaches and better than the self-compositional approach.
引用
收藏
页码:352 / 367
页数:16
相关论文
共 50 条
  • [21] Secure information flow by self-composition
    Barthe, G
    D'Argenio, PR
    Rezk, T
    17TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS, 2004, : 100 - 114
  • [22] A type system for computationally secure information flow
    Laud, P
    Vene, V
    FUNDAMENTALS OF COMPUTATIONAL THEORY, PROCEEDINGS, 2005, 3623 : 365 - 377
  • [23] A Method of Secure Information Flow Based on Data Flow Analysis
    Yao, Jianbo
    SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING: THEORY AND PRACTICE, VOL 1, 2012, 114 : 597 - 606
  • [24] LATTICE MODEL OF SECURE INFORMATION-FLOW
    DENNING, DE
    COMMUNICATIONS OF THE ACM, 1976, 19 (05) : 236 - 243
  • [25] Secure information flow as typed process behaviour
    Honda, K
    Vasconcelos, V
    Yoshida, N
    PROGRAMMING LANGUAGES AND SYSTEMS, PROCEEDINGS, 2000, 1782 : 180 - 199
  • [26] Dynamic dependency monitoring to secure information flow
    Shroff, Paritosh
    Smith, Scott F.
    Thober, Mark
    20TH IEEE COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSFS20), PROCEEDINGS, 2007, : 203 - +
  • [27] CERTIFICATION OF PROGRAMS FOR SECURE INFORMATION-FLOW
    DENNING, DE
    DENNING, PJ
    COMMUNICATIONS OF THE ACM, 1977, 20 (07) : 504 - 513
  • [28] Handling encryption in an analysis for secure information flow
    Laud, P
    PROGRAMMING LANGUAGES AND SYSTEMS, 2003, 2618 : 159 - 173
  • [29] A Secure Information Flow Architecture for Web Services
    Singaravelu, Lenin
    Wei, Jinpeng
    Pu, Calton
    2008 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, VOL 1, 2008, : 182 - 189
  • [30] A uniform type structure for secure information flow
    Honda, K
    Yoshida, N
    ACM SIGPLAN NOTICES, 2002, 37 (01) : 81 - 92