A Taxonomy of Information Flow Monitors

نویسندگان

  • Nataliia Bielova
  • Tamara Rezk
چکیده

We propose a rigorous comparison of information flow monitors with respect to two dimensions: soundness and transparency. For soundness, we notice that the standard information flow security definition called Termination-Insensitive Noninterference (TINI) allows the presence of termination channels, however it does not describe whether the termination channel was present in the original program, or it was added by a monitor. We propose a stronger notion of noninterference, that we call Termination-Aware Noninterference (TANI), that captures this fact, and thus allows us to better evaluate the security guarantees of different monitors. We further investigate TANI, and state its formal relations to other soundness guarantees of information flow monitors. For transparency, we identify different notions from the literature that aim at comparing the behaviour of monitors. We notice that one common notion used in the literature is not adequate since it identifies as better a monitor that accepts insecure executions, and hence may augment the knowledge of the attacker. To discriminate between monitors’ behaviours on secure and insecure executions, we factorized two notions that we call true and false transparency. These notions allow us to compare monitors that were deemed to be incomparable in the past. We analyse five widely explored information flow monitors: no-sensitiveupgrade (NSU), permissive-upgrade (PU), hybrid monitor (HM), secure multi-execution (SME), and multiple facets (MF).

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Low cost air quality monitors to evaluate nanosized particulate matter. A pilot study

Particulate matter is defined as a mixture of airborne solid particles and liquid droplets that can be inhaled and may cause serious health problems. Such elements are currently measured utilizing air quality monitoring devices that provide information on PM 10 and PM 2.5 levels giving information on pollution levels. However, many difficulties are encountered in the determination of nanosized ...

متن کامل

Power Quality Monitor Placement Using a Tri-level Approach

Finding minimum number of connecting lines is as important as locating power quality monitors (PQMs) for full observability of power system. Therefore, a PQM placement method should determine both optimum buses and lines, since utilities can make better decisions for monitoring of power system with this information. This paper attempted to propose a new method to locate the PQMs at various unob...

متن کامل

On-the-Fly Inlining of Dynamic Dependency Monitors for Secure Information Flow

Information flow analysis (IFA) in the setting of programming languages is steadily veering towards the adoption of dynamic techniques. This is particularly attractive for scripting languages for web applications programming. A common manifestation of dynamic techniques is that of run-time monitors, which should block program execution in the presence of an insecure run. Significant efforts are...

متن کامل

Global and Local Monitors to Enforce Noninterference in Concurrent Programs

Controlling confidential information in concurrentsystems is difficult, due to covert channels resulting from inter-action between threads. This problem is exacerbated if threadsshare resources at fine granularity.In this work, we propose a novel monitoring framework toenforce strong information security in concurrent programs. Ourmonitors are hybrid, combining dynamic a...

متن کامل

A Taxonomy for Information Flow Policies and Models

This paper proposes a notation for describing information flow policies that can express transitive, aggwga-tion and separation (of duty) exceptions. Operators for comparing, composing and abstracting flow policies are described. These atlow complex policies to be built from simpler policies. Many existing confidentiality (and by ) using a dual model, integrity policies and their models can be ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016