Runtime Enforcement of Security Policies on Black Box Reactive Programs

Runtime Enforcement of Security Policies on Black Box Reactive Programs
复制标题

黑盒反应程序安全策略的运行时执行

DOI:
10.1145/2775051.2676978
复制
发表时间:
2015
影响因子:
--
通讯作者:
Frank Piessens
Frank Piessens
中科院分区:
--
文献类型:
--
作者:
Minh Ngo;F. Massacci;Dimiter Milushev;Frank Piessens

文献摘要

被引文献

相似文献

执行监视器等安全强制机制用于确保某些不受信任的程序遵守策略。不同的执行机制有不同的优点和缺点,因此了解各种执行机制的质量是很重要的。本文研究了反应式程序的运行时执行机制。我们研究了许多实际执行机制所满足的两个重要约束的影响:(1)执行机制必须在有限的时间内处理每个输入/输出事件,并在事件发生时处理(与例如Ligatti的编辑自动机相反,其具有在任意时间量内缓冲事件的能力),以及(2)强制机制将不可信程序视为黑盒:它可以监视和/或编辑程序在执行时展示的输入/输出事件,并且它可以通过运行程序的附加副本并提供这些不同的输入来探索程序的替代执行。它不能检查不可信程序的源代码或机器代码。这样的执行机制在实践中是重要的:它们包括例如许多执行监视器、虚拟机监视器和安全多执行或影子执行。我们建立的上限和下限的类的政策,可执行的黑箱机制,我们提出了一个通用的执行机制,适用于广泛的政策。我们还展示了如何我们的通用执行机制可以被实例化,以执行特定类别的政策,同时表明,许多现有的执行机制是我们的建设优化的实例。
Security enforcement mechanisms like execution monitors are used to make sure that some untrusted program complies with a policy. Different enforcement mechanisms have different strengths and weaknesses and hence it is important to understand the qualities of various enforcement mechanisms. This paper studies runtime enforcement mechanisms for reactive programs. We study the impact of two important constraints that many practical enforcement mechanisms satisfy: (1) the enforcement mechanism must handle each input/output event in finite time and on occurrence of the event (as opposed to for instance Ligatti's edit automata that have the power to buffer events for an arbitrary amount of time), and (2) the enforcement mechanism treats the untrusted program as a black box: it can monitor and/or edit the input/output events that the program exhibits on execution and it can explore alternative executions of the program by running additional copies of the program and providing these different inputs. It can not inspect the source or machine code of the untrusted program. Such enforcement mechanisms are important in practice: they include for instance many execution monitors, virtual machine monitors, and secure multi-execution or shadow executions. We establish upper and lower bounds for the class of policies that are enforceable by such black box mechanisms, and we propose a generic enforcement mechanism that works for a wide range of policies. We also show how our generic enforcement mechanism can be instantiated to enforce specific classes of policies, at the same time showing that many existing enforcement mechanisms are optimized instances of our construction.