eCommons

 

Beyond Labels: Permissiveness for Dynamic Information Flow Enforcement

dc.contributor.authorKozyri, Elisavet
dc.contributor.authorSchneider, Fred B.
dc.contributor.authorBedford, Andrew
dc.contributor.authorDesharnais, Josée
dc.contributor.authorTawbi, Nadia
dc.date.accessioned2019-02-28T18:02:12Z
dc.date.available2019-02-28T18:02:12Z
dc.date.issued2019-02-28
dc.description.abstractFlow-sensitive labels used by dynamic enforcement mechanisms might themselves encode sensitive information, which can leak. Metalabels, employed to represent the sensitivity of labels, exhibit the same problem. This paper derives a new family of enforcers k-Enf , for k>1 that uses label chains, where each label defines the sensitivity of its predecessor. These enforcers satisfy Block-safe Noninterference (BNI), which proscribes leaks from observing variables, label chains, and blocked executions. Theorems in this paper characterize where longer label chains can improve the permissiveness of dynamic enforcement mechanisms that satisfy BNI. These theorems depend on semantic attributes---k-precise, k-varying, and k-dependent---of such mechanisms, as well as on initialization, threat model, and lattice size.en_US
dc.identifier.urihttps://hdl.handle.net/1813/64488
dc.language.isoen_USen_US
dc.relation.isreplacedbyhttps://hdl.handle.net/1813/64488.2
dc.rightsAttribution-NonCommercial-ShareAlike 4.0 International*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-sa/4.0/*
dc.subjectinformation flow controlen_US
dc.subjectdynamicen_US
dc.subjectflow-sensitiveen_US
dc.subjectpermissivenessen_US
dc.subjectlabel chainsen_US
dc.titleBeyond Labels: Permissiveness for Dynamic Information Flow Enforcementen_US
dc.typetechnical reporten_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
paper.pdf
Size:
643.97 KB
Format:
Adobe Portable Document Format
Description:
Mail article

Version History

Now showing 1 - 2 of 2
VersionDateSummary
2019-05-09 11:11:17
Explanatory sentences added throughout text. Important definitions placed in displays, rearranged definitions in section 3, and added acknowledgement section.
1*
2019-02-28 13:02:12
* Selected version