Breaking the Model: Finalisation and a Taxonomy of Security Attacks

Breaking the Model: Finalisation and a Taxonomy of Security Attacks
复制标题

DOI:
10.1016/j.entcs.2005.04.033
复制
发表时间:
2005-07-21
影响因子:
--
通讯作者:
Chivers, Howard
Chivers, Howard
中科院分区:
其他
文献类型:
--
作者:
Clark, John A.;Stepney, Susan;Chivers, Howard

文献摘要

被引文献

相似文献

众所周知,安全属性不能通过细化来保持,并且细化可以引入新的隐蔽信道,例如定时信道。细化中的最终化步骤可以被分析以识别其中的一些通道,作为可以打破正式模型的假设的不需要的最终化。我们介绍了这种不必要的终结的分类,并给出了利用它们的攻击的例子。
It is well known that security properties are not preserved by refinement, and that refinement can introduce new, covert, channels, such as timing channels. The finalisation step in refinement can be analysed to identify some of these channels, as unwanted finalisations that can break the assumptions of the formal model. We introduce a taxonomy of such unwanted finalisations, and give examples of attacks that exploit them.