A Perspective on Information-Flow Control

نویسندگان

  • Daniel Hedin
  • Andrei Sabelfeld
چکیده

Information-flow control tracks how information propagates through the program during execution to make sure that the program handles the information securely. Secure information flow is comprised of two related aspects: information confidentiality and information integrity — intuitively pertaining to the reading and writing of the information. The prevailing basic semantic notion of secure information flow is noninterference, demanding independence of public (or, in the case of integrity, trusted) output from secret (or, in the case of integrity, untrusted) input. This document gives an account of the state-of-the-art in confidentiality and integrity policies and their enforcement with a systematic formalization of four dominant formulations of noninterference: termination-insensitive, termination-sensitive, progress-insensitive, and progress-sensitive, cast in the setting of two minimal while languages. 1. Information-flow control The control of how information is propagated by computing systems is vital for information security. Historically, access control has been the main means of preventing information from being disseminated. As the name indicates, access control verifies that the program’s access rights at the point of access, and either grants or denies the program access. Once the program has been given access to information no further effort is made to make sure that the program handles the accessed information correctly. However, access control is inadequate in many situations, since it forces an all-or-nothing choice of either fully trusting the program not to leak/compromise information or not allowing access to this information altogether. Information-flow control tracks how information propagates through the program during execution to make sure that the program handles the information securely. The research on secure information flow goes back to the early 70’s [35,39], primarily in the context of military systems. Secure information flow is comprised of two related aspects: information confidentiality and information integrity — intuitively pertaining to the reading and writing of the information. The prevailing basic semantic notion of secure information flow is noninterference [46], demanding independence of public (or, in the case of integrity, trusted) output from secret (or, in the case of integrity, untrusted) input. As the field has matured, numerous variations of noninterference [98], as well as other semantic characterizations have been explored [103]. Recently, information integrity has received attention [55,57,19,4]. Integrity has frequently been seen as the dual of confidentiality [18], though it can be argued that this description might ignore other important facets [19]. One important aspect of integrity lies in its interaction with declassification — intentional lowering of security classification of information — in order to prevent the attacker from controlling what information is declassified [77,78]. Below we give an account of the state-of-the-art in confidentiality and integrity policies and enforcement, with a detailed exposition of various formulations of noninterference.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Information and data flow analysis for forestry sector in Iran as a basic requirement for designing a forest information system (FIS)

ABSTRACT The aim of this study was to evaluate the status of information on forest and data transfer and to identify the gaps in information and data flow in forestry sector in Iran. The study evaluated the data and information flow in three levels (control offices level, provincial offices level and organizational offices level) using the document analysis and questioning (interviews and ques...

متن کامل

Access to information in natural disaster management in in Iran: stakeholders’ perspective

Background and objective: Access to information is one of the pillars of a smooth and productive information flow which would provide the best opportunities for an effective Information management. Thus, it is essential to acquire the knowledge about how to access information and ways to improve it, especially in the field of natural disaster management (NDM), which is based on decisions making...

متن کامل

Analyzing the 60-day low flow from upstream to downstream in the Karkeh Basin

Knowing how the low flow changes upstream and its trend provides valuable information on water resources management, water rights, and the improvement of crop patterns. It also helps to identify suitable areas for water control management along the river from water resources management perspective. In addition to economic issues, the preservation of river ecosystems is an important matter that ...

متن کامل

The effects of outside board on firm value in Tehran Stock Exchange from the perspective of information transaction costs

The aim of this study is to investigate the effects of outside board on rm value in Tehran Stock Exchange (TSE) from the perspective of information transaction costs. To do so, a sample of 96 firms listed in TSE is selected to be studied during the period of 2003-2012. Tobin q ratio is used to measure rm's value and bid-ask spread for information transaction costs. In addition to these variable...

متن کامل

Consistency Checking for Workflows with an Ontology-Based Data Perspective

Static analysis techniques for consistency checking of workflows allow to avoid runtime errors. This is in particular crucial for long running workflows where errors detected late can cause high costs. Checking techniques can analyse the control flow of individual tasks as well as the consistency of how data of the workflow is represented, collected and utilized. In many classes of workflows, t...

متن کامل

A Perspective on Promoter Ownership and Market Reaction to Corporate News: Evidence from India

C orporate governance structures in the wake of observed differences in firm ownership structures in developed markets and emerging market economies are distinct. In this paper, we examine the effect of an ownership structure of firms on the market reaction to corporate news flows in the context of emerging market economies like India. We observe the price and volume movements associ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012