Attacker Control and Impact for Confidentiality and Integrity

Attacker Control and Impact for Confidentiality and Integrity
复制标题

攻击者对机密性和完整性的控制和影响

DOI:
--
复制
发表时间:
2011
期刊:
Log. Methods Comput. Sci.
影响因子:
--
通讯作者:
A. Myers
A. Myers
中科院分区:
--
文献类型:
--
作者:
Aslan Askarov;A. Myers

文献摘要

被引文献

相似文献

基于数据的信息流方法提供了一种原则性的方法, 强大的安全属性,但强制不干涉太不灵活, 现实的应用。因此,安全类型语言引入了 放松保密政策的解密机制,以及 放宽诚信政策的认可机制。然而,持续的 一个挑战是确定当这种机制 被使用。本文提出了一种新的安全性语义表达框架 在以语言为基础的环境中的解密和认可政策。的 一个关键的观点是,安全可以用影响力来描述, 解密和认可允许攻击者。新框架 引入了两个安全概念来描述攻击者的影响。 攻击者控制定义了攻击者能够从Observable中学习到什么 此代码的影响;攻击者影响捕获攻击者对 可信的位置。这种方法产生了新的安全条件检查 认可和强大的完整性。框架足够灵活, 并改进以前引入的鲁棒性和合格的概念, 鲁棒性此外,新的安全条件可以通过 安全类型系统。新政策的适用性和执行情况 通过各种示例来说明,包括数据清理和 身份验证
Language-based information flow methods offer a principled way to enforce strong security properties, but enforcing noninterference is too inflexible for realistic applications. Security-typed languages have therefore introduced declassification mechanisms for relaxing confidentiality policies, and endorsement mechanisms for relaxing integrity policies. However, a continuing challenge has been to define what security is guaranteed when such mechanisms are used. This paper presents a new semantic framework for expressing security policies for declassification and endorsement in a language-based setting. The key insight is that security can be characterized in terms of the influence that declassification and endorsement allow to the attacker. The new framework introduces two notions of security to describe the influence of the attacker. Attacker control defines what the attacker is able to learn from observable effects of this code; attacker impact captures the attacker's influence on trusted locations. This approach yields novel security conditions for checked endorsements and robust integrity. The framework is flexible enough to recover and to improve on the previously introduced notions of robustness and qualified robustness. Further, the new security conditions can be soundly enforced by a security type system. The applicability and enforcement of the new policies is illustrated through various examples, including data sanitization and authentication.