Interprocedural Information Flow Analysis of XML Processors

Interprocedural Information Flow Analysis of XML Processors
复制标题

XML 处理器的过程间信息流分析

DOI:
10.1007/978-3-319-04921-2_4
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
Máté Kovács
Máté Kovács
中科院分区:
--
文献类型:
--
作者:
Helmut Seidl;Máté Kovács

文献摘要

参考文献

被引文献

相似文献

提供可公开访问的Web服务时的一个关键问题是,敏感数据应该只能由授权用户访问。应用程序或信息流中数据的可访问性可以方便地形式化为程序的2-超属性。在这里,我们提出了一种技术,在XML处理器中的信息流进行交互分析。我们的方法是基于程序匹配的一般技术,以及由此产生的2-程序的关系抽象解释。在XML处理器的情况下,抽象的关系语义可以通过有限树自动机进行实际分析。
A crucial issue when providing publicly accessible web services is that sensitive data should only be accessible by authorized users. Accessibility of data within an application or information flow can conveniently be formalized as a 2-hyperproperty of a program. Here, we present a technique to interprocedurally analyze information flow in XML processors. Our approach is based on general techniques for program matching, and relational abstract interpretation of the resulting 2-programs. In case of XML processors, the abstract relational semantics then can be practically analyzed by means of finite tree automata.
DOI: --
发表时间: 1977
期刊: Formal Description of Programming Concepts
影响因子: --
作者:
P. Cousot;R. Cousot
通讯作者: R. Cousot
DOI: 10.1007/11547662_24
发表时间: 2005-09
期刊: --
影响因子: --
作者:
Tachio Terauchi;A. Aiken
通讯作者: Tachio Terauchi;A. Aiken
超越2-安全性:用于关系程序验证的非对称产品程序
DOI: 10.1007/978-3-642-35722-0_3
发表时间: 2013
期刊: The Lancet
影响因子: --
作者:
G. Barthe;Juan Manuel Crespo;César Kunz
通讯作者: César Kunz
DOI: --
发表时间: 1992
期刊: International Conference on Compiler Construction
影响因子: --
作者:
J. Knoop;B. Steffen
通讯作者: B. Steffen
DOI: 10.1007/3-540-48660-7_29
发表时间: 1999-07
期刊: --
影响因子: --
作者:
Christoph Weidenbach
通讯作者: Christoph Weidenbach