Runtime Enforcement of Information Flow Security in Tree Manipulating Processes
Runtime Enforcement of Information Flow Security in Tree Manipulating Processes
复制标题
DOI:
10.1007/978-3-642-28166-2_6
复制
发表时间:
2012-02
期刊:
影响因子:
--
通讯作者:
Máté Kovács;H. Seidl
中科院分区:
文献类型:
--
作者:
Máté Kovács;H. Seidl
We consider the problem of enforcing information flow policies inXmlmanipulating programs such as Web services and business processes implemented in current workflow languages. We propose a runtime monitor that can enforce the secrecy of freely chosen subtrees of the data throughout the execution. The key idea is to apply a generalizedconstant propagationfor computing the public effect of branching constructs whose conditions may depend on the secret. This allows for a better precision than runtime monitors which rely on tainting of variables or nodes alone. We demonstrate our approach for a minimalistic tree manipulating programming language and prove its correctness w.r.t. the concrete semantics of programs.