It's My Privilege: Controlling Downgrading in DC-Labels

نویسندگان

  • Lucas Waye
  • Pablo Buiras
  • Dan King
  • Stephen Chong
  • Alejandro Russo
چکیده

Disjunction Category Labels (DC-labels) are an expressive label format used to classify the sensitivity of data in information-flow control systems. DC-labels use capability-like privileges to downgrade information. Inappropriate use of privileges can compromise security, but DC-labels provide no mechanism to ensure appropriate use. We extend DC-labels with the novel notions of bounded privileges and robust privileges. Bounded privileges specify and enforce upper and lower bounds on the labels of data that may be downgraded. Bounded privileges are simple and intuitive, yet can express a rich set of desirable security policies. Robust privileges can be used only in downgrading operations that are robust, i.e., the code exercising privileges cannot be abused to release or certify more information than intended. Surprisingly, robust downgrades can be expressed in DC-labels as downgrading operations using a weakened privilege. We provide sound and complete run-time security checks to ensure downgrading operations are robust. We illustrate the applicability of bounded and robust privileges in a case study as well as by identifying a vulnerability in an existing DC-label-based application.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Disjunction Category Labels

We present disjunction category (DC) labels, a new label format for enforcing information flow in the presence of mutually distrusting parties. DC labels can be ordered to form a lattice, based on propositional logic implication and conjunctive normal form. We introduce and prove soundness of decentralized privileges that are used in declassifying data, in addition to providing a notion of priv...

متن کامل

JRIF: Reactive Information Flow Control for Java∗ Technical Report

Classic information flow systems conservatively define the security label associated with a derived value to be at least as restrictive as the security label on any input to that derivation. Because restrictions on information flow do not necessarily change monotonically over time, this definition requires programmers to invoke downgrading operations. A reactive information flow (RIF) specifica...

متن کامل

The Unbearable Lightness of Being1

'd prefer to remain a mystery. I never like to give my background and, anyway, I make it all up different every time I'm asked, " Andy Warhol said. " It's not just that it's part of my image not to tell anything, it's just that I forget what I said the day before, and I have to make it all up over again. " The man described as " a serious artist whose posture was unseriousness " called himself ...

متن کامل

Computational and modelling power of P systems

Acknowledgments I am very grateful to all the people I had the privilege to work with, in par-Above all, I would like to thank my advisor Giancarlo Mauri, for his constant interest, encouragement and help. It is a pleasure to take this occasion to thank all the scientists I have met and been in contact with. In particular, my warmest thanks and indebtedness go to Erzsébet Csuhaj–Varjú and Mario...

متن کامل

Effect of Akt (PKB) on the activity of mammalian target of rapamycin (mTOR)

Acknowledgments This thesis is dedicated to the loving memories of my grandmother Elli Schumann " Oma Elli " and Dirk's mother Edith Windgassen. Both, very important women in our lives, died at young ages from breast cancer. I am very grateful for the tremendous scientific direction and environment provided to me by my thesis advisor Prof. Dr. Nissim Hay. He allows all students to grow as scien...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015