Static Analysis of Security Properties in Mobile Ambients
نویسندگان
چکیده
Security is a major concern for computation in wide-area networks, and is often considered a serious source of potential limitation to a widespread use of mobile code technologies. This key issue has stimulated the research on efficient validation and verification techniques ensuring the acceptable behaviour of software components roaming around on information networks. In this dissertation, we study the impact of an analysis methodology based on control flow analysis in flow logic style on the verification of information-flow security properties in the calculus of Mobile Ambients. The ambient calculus is a minimal formalism where the notion of ambient captures the structure and properties of wide area networks, mobile computing, and mobile computation. As a second contribution, we develop an effective framework for building and analysing systems relying on Rôle-based Access Control mechanisms. In particular, by relying on strong typing as the basic principle, we develop type theoretic methods and tools ensuring that the specified policy is respected during computations. Concern for man himself and his safety must always form the chief interest of all technical endeavours. Never forget this in the midst of your diagrams and equations.
منابع مشابه
Boundary Inference for Enforcing Security Policies in Mobile Ambients
The notion of “boundary ambient” has been recently introduced to model multilevel security policies in the scenario of mobile systems, within pure Mobile Ambients calculus. Information flow is defined in terms of the possibility for a confidential ambient/data to move outside a security boundary, and boundary crossings can be captured through a suitable Control Flow Analysis. We show that this ...
متن کاملInformation flow security in Boundary Ambients
A variant of the Mobile Ambient calculus, called Boundary Ambients, is introduced, supporting the modelling of multi-level security policies. Ambients that may guarantee to properly protect their content are explicitly identified as boundaries: a boundary can be seen as a resource access manager for confidential data. In this setting, absence of direct information leakage is granted as soon as ...
متن کاملInformation Flow Security in Boxed Ambients
We study the problem of secure information flow for Boxed Ambients in terms of non-interference. We develop a sound type system that provides static guarantees of absenceof unwanted flow of information for well typed processes. Non-interference is stated, andproved, in terms of a typed notion of contextual equivalence for Boxed Ambients akin tothe corresponding equivalence d...
متن کاملAbstract Interpretation-Based Static Analysis of Mobile Ambients
Interpretation-Based Static Analysis of Mobile Ambients
متن کاملParametric model checking for Mobile Ambients
In this paper we propose an new abstract finite model of Mobile Ambients able to express some interesting security properties. This model can be used for analysing these properties by means of model checking techniques. The precision of the analysis can be increased by modifying certain parameters of the model increasingly avoiding thereby the occurrences of false counterexamples.
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005