On Quantitative Security Policies

نویسندگان

  • Pierpaolo Degano
  • Gian Luigi Ferrari
  • Gianluca Mezzetti
چکیده

We introduce a formal framework to specify and enforce quantitative security policies. The framework consists of: (i) a stochastic process calculus to express the measurable space of computations in terms of Continuous Time Markov Chains; (ii) a stochastic modal logic (a variant of CSL) to represent the bound constraints on execution speed; (iii) two enforcement mechanisms of our quantitative security policies: potential or actual. The potential enforcement computes the probability of policy violations, thus providing a sort of static evaluation of the policy. This supports the user to accept/discard a component when the probability of the security violation is below/above a suitable chosen threshold. The actual enforcement computes the deviation of the execution speed from the acceptable rate. This supports the run-time systems by driving the execution monitor to abort unsafe executions.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Survey of Quantitative Information Flow

Traditional information flow security policies declare that many useful and necessary programs are insecure. This results from the qualitative nature of these policies: either information flows, or it does not. A richer class of security properties that can express the degree of information flow is needed; we call these quantitative information flow policies. Such policies have recently become ...

متن کامل

Gender Analysis of Social Security Policies in Post- Revolutionary Iran

Introduction: Due to the fact that gender is important as the most basic pillar of individuals ’identities in all social relations, it is helpful to identify current deficiencies in policymaking. Method: The method used is qualitative content analysis in the  gender analysis approach. To this end, the documents and approvals of the main womenchr(chr(chr('39')39chr('39'))39chr(chr('39')39chr('3...

متن کامل

Gender Analysis of Social Security Policies in Post- Revolutionary Iran

Introduction: Due to the fact that gender is important as the most basic pillar of individuals ’identities in all social relations, it is helpful to identify current deficiencies in policymaking. Method: The method used is qualitative content analysis in the  gender analysis approach. To this end, the documents and approvals of the main womenchr(chr(chr('39')39chr('39'))39chr(chr('39')39chr('3...

متن کامل

Evaluating Energy Policies through the Use of a Hybrid Quantitative Indicator-Based Approach: The Case of Mercosur

This paper evaluates the performance of energy policies in the Southern Common Market (Mercosur), a regional initiative consisting of Argentina, Brazil, Paraguay and Uruguay, but also considering Venezuela (full member since mid-2012) and Bolivia (full participation under negotiation since 2015). The methodology is based on a qualitative-quantitative approach. First, we provide a critical revie...

متن کامل

Quantitative evaluation of software security: an approach based on UML/SecAM and evidence theory

Quantitative and model-based prediction of security in the architecture design stage facilitates early detection of design faults hence reducing modification costs in subsequent stages of software life cycle. However, an important question arises with respect to the accuracy of input parameters. In practice, security parameters can rarely be estimated accurately due to the lack of sufficient kn...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011