Data and Applications Security and Privacy XXXI - 31st Annual IFIP WG 11.3 Conference, DBSec 2017, Philadelphia, PA, USA, July 19-21, 2017, Proceedings

Data and Applications Security and Privacy XXXI - 31st Annual IFIP WG 11.3 Conference, DBSec 2017, Philadelphia, PA, USA, July 19-21, 2017, Proceedings
复制标题

数据和应用程序安全与隐私 XXXI - 第 31 届年度 IFIP WG 11.3 会议,DBSec 2017,美国宾夕法尼亚州费城,2017 年 7 月 19-21 日,会议记录

DOI:
10.1007/978-3-319-61176-1_3
复制
发表时间:
2017
期刊:
--
影响因子:
--
通讯作者:
Uzun E
Uzun E
中科院分区:
--
文献类型:
--
作者:
Uzun E

文献摘要

相似文献

特洛伊木马攻击可能导致未经授权的数据流,并可能导致违反机密性或违反完整性。解决该问题的现有解决方案采用跟踪所有主体对对象的访问的分析技术,因此可能是昂贵的。在本文中,我们表明,对于一个未经授权的流量存在于访问控制矩阵,一定存在一个流的长度。因此,为了消除未经授权的流,删除所有单步流就足够了,从而避免了对昂贵的传递闭包计算的需要。这种新的见解使我们能够开发一种有效的方法来识别和防止所有导致机密性和完整性违规的未经授权的流量。我们开发单独的解决方案,发生在真实的生活中的两个不同的环境,并实验验证所提出的方法使用真实的数据集的效率和限制性。
Trojan Horse attacks can lead to unauthorized data flows and can cause either a confidentiality violation or an integrity violation. Existing solutions to address this problem employ analysis techniques that keep track of all subject accesses to objects, and hence can be expensive. In this paper we show that for an unauthorized flow to exist in an access control matrix, a flow of length one must exist. Thus, to eliminate unauthorized flows, it is sufficient to remove all one-step flows, thereby avoiding the need for expensive transitive closure computations. This new insight allows us to develop an efficient methodology to identify and prevent all unauthorized flows leading to confidentiality and integrity violations. We develop separate solutions for two different environments that occur in real life, and experimentally validate the efficiency and restrictiveness of the proposed approaches using real data sets.