TY - GEN
T1 - Programmable enforcement framework of information flow policies
AU - Ngo, M.
AU - Massacci, F.
PY - 2014
Y1 - 2014
N2 - We propose a programmable framework that can be easily instantiated to enforce a large variety of information flow properties. Our framework is based on the idea of secure multi-execution in which multiple instances of the controlled program are executed in parallel. The information flow property of choice can be obtained by simply implementing programs that control parallel executions. We present the architecture of the enforcement mechanism and its instantiations for non-interference (NI) (from Devriese and Piessens), non-deducibility (ND) (from Sutherland) and some properties proposed by Mantel, such as removal of inputs (RI) and deletion of inputs (DI), and demonstrate formally soundness and precision of enforcement for these properties.
AB - We propose a programmable framework that can be easily instantiated to enforce a large variety of information flow properties. Our framework is based on the idea of secure multi-execution in which multiple instances of the controlled program are executed in parallel. The information flow property of choice can be obtained by simply implementing programs that control parallel executions. We present the architecture of the enforcement mechanism and its instantiations for non-interference (NI) (from Devriese and Piessens), non-deducibility (ND) (from Sutherland) and some properties proposed by Mantel, such as removal of inputs (RI) and deletion of inputs (DI), and demonstrate formally soundness and precision of enforcement for these properties.
UR - https://www.scopus.com/pages/publications/84908543890
UR - https://www.scopus.com/inward/citedby.url?scp=84908543890&partnerID=8YFLogxK
M3 - Conference contribution
T3 - CEUR Workshop Proceedings
SP - 197
EP - 211
BT - ICTCS 2014 - Proceedings of the 15th Italian Conference on Theoretical Computer Science
A2 - Formisano, A.
A2 - Bistarelli, S.
PB - CEUR-WS
T2 - 15th Italian Conference on Theoretical Computer Science, ICTCS 2014
Y2 - 17 September 2014 through 19 September 2014
ER -