Hybrid Monitoring of Attacker Knowledge

Hybrid Monitoring of Attacker Knowledge
复制标题

攻击者知识的混合监控

DOI:
10.1109/csf.2016.23
复制
发表时间:
2016
期刊:
2016 IEEE 29th Computer Security Foundations Symposium (CSF)
影响因子:
--
通讯作者:
T. Jensen
T. Jensen
中科院分区:
--
文献类型:
--
作者:
Frédéric Besson;Nataliia Bielova;T. Jensen

文献摘要

参考文献

被引文献

相似文献

强制执行不干涉要求证明攻击者在观察程序的公共输出后,对初始状态的了解保持不变。我们提出了一种混合监测机制,动态评估的知识,包含在程序变量。为了获得对知识的精确估计,监视器静态地分析未执行的分支。我们表明,我们的知识为基础的监视器可以与现有的动态监视器不干扰。这种组合的一个显著特征是,组合的监控器可以证明比单独采用的每个机制更宽容。我们证明了这一点,提出了一个知识增强版本的无敏感升级(NSU)监视器。监视器及其静态分析已在Coq证明助手中形式化并证明是正确的。
Enforcement of noninterference requires proving that an attacker's knowledge about the initial state remains the same after observing a program's public output. We propose a hybrid monitoring mechanism which dynamically evaluates the knowledge that is contained in program variables. To get a precise estimate of the knowledge, the monitor statically analyses non-executed branches. We show that our knowledge-based monitor can be combined with existing dynamic monitors for non-interference. A distinguishing feature of such a combination is that the combined monitor is provably more permissive than each mechanism taken separately. We demonstrate this by proposing a knowledge-enhanced version of a no-sensitive-upgrade (NSU) monitor. The monitor and its static analysis have been formalized and proved correct within the Coq proof assistant.
DOI: 10.1145/1111037.1111045
发表时间: 2006-01
期刊: --
影响因子: --
作者:
Sebastian Hunt;David Sands
通讯作者: Sebastian Hunt;David Sands
DOI: 10.1109/csf.2015.33
发表时间: 2015
期刊: 2015 IEEE 28th Computer Security Foundations Symposium
影响因子: --
作者:
Christian Müller;Máté Kovács;Helmut Seidl
通讯作者: Helmut Seidl