Stateful Declassification Policies for Event-Driven Programs

Stateful Declassification Policies for Event-Driven Programs
复制标题

事件驱动程序的状态解密策略

DOI:
10.1109/csf.2014.28
复制
发表时间:
2014
期刊:
2014 IEEE 27th Computer Security Foundations Symposium
影响因子:
--
通讯作者:
Tamara Rezk
Tamara Rezk
中科院分区:
--
文献类型:
--
作者:
M. Vanhoef;Willem De Groef;Dominique Devriese;Frank Piessens;Tamara Rezk

文献摘要

被引文献

相似文献

我们提出了一种新的机制来执行信息流策略,支持事件驱动程序的解密。解密策略包括两个功能。首先,投影函数为每个机密事件指定事件中的哪些信息可以直接解密。这概括了输入的传统安全标签。其次,有状态发布函数指定迄今为止可以解密的所有机密事件的汇总信息。我们提供的证据表明,这种解密策略在Java Script web应用程序的上下文中是有用的。提出了我国政策的执行机制,并证明了其合理性和精确性。最后,我们通过在浏览器中实现和评估该机制来证明其实用性。
We propose a novel mechanism for enforcing information flow policies with support for declassification on event-driven programs. Declassification policies consist of two functions. First, a projection function specifies for each confidential event what information in the event can be declassified directly. This generalizes the traditional security labelling of inputs. Second, a stateful release function specifies the aggregate information about all confidential events seen so far that can be declassified. We provide evidence that such declassification policies are useful in the context of Java Script web applications. An enforcement mechanism for our policies is presented and its soundness and precision is proven. Finally, we give evidence of practicality by implementing and evaluating the mechanism in a browser.