Runtime Enforcement of Information Flow Security in Tree Manipulating Processes

Runtime Enforcement of Information Flow Security in Tree Manipulating Processes
复制标题

DOI:
10.1007/978-3-642-28166-2_6
复制
发表时间:
2012-02
期刊:
--
影响因子:
--
通讯作者:
Máté Kovács;H. Seidl
Máté Kovács;H. Seidl
中科院分区:
其他
文献类型:
--
作者:
Máté Kovács;H. Seidl

文献摘要

被引文献

相似文献

我们考虑的问题,强制执行的信息流策略在XML操纵程序,如Web服务和业务流程,在当前的工作流语言实现。我们提出了一个运行时监视器,可以强制执行整个执行过程中的数据的自由选择的子树的秘密。其核心思想是应用广义常数传播来计算分支结构的公共效应,其条件可能取决于秘密。这允许比运行时监视器更好的精度,运行时监视器仅依赖于变量或节点的污染。我们展示了我们的方法,最低限度的树操纵编程语言,并证明其正确性w.r.t.程序的具体语义。
We consider the problem of enforcing information flow policies inXmlmanipulating programs such as Web services and business processes implemented in current workflow languages. We propose a runtime monitor that can enforce the secrecy of freely chosen subtrees of the data throughout the execution. The key idea is to apply a generalizedconstant propagationfor computing the public effect of branching constructs whose conditions may depend on the secret. This allows for a better precision than runtime monitors which rely on tainting of variables or nodes alone. We demonstrate our approach for a minimalistic tree manipulating programming language and prove its correctness w.r.t. the concrete semantics of programs.