返回
Language-based information-flow security
DOI:10.1109/JSAC.2002.806121.png)
摘要
En 中文
Current standard security practices do not provide substantial assurance that the end-to-end behavior of a computing system satisfies important security policies such as confidentiality. An end-to-end confidentiality policy might assert that secret input data cannot be inferred by an attacker through the attacker's observations of system output; this policy regulates information flow. Conventional security mechanisms such as access control and encryption do not directly address the enforcement of information-flow policies. Recently, a promising new approach has been developed: the use of programming-language techniques for specifying and enforcing information-flow policies. In this paper, we survey the past three decades of research on information-flow security, particularly focusing on work that uses static program analysis to enforce information-flow policies. We give a structured view of recent work in the area and identify some important open challenges.
Keyword:
computer security
concurrency
confidentiality
covert channels
information flow
noninterference
security policies
security-type systems
期刊
IF:
17.2
论文数:
6.4K
被引数:
3.1W
机构
暂无机构信息
引用论文
Identification of Gastric Cancer–Related Genes Using a cDNA Microarray Containing Novel Expressed Sequence Tags Expressed in Gastric Cancer Cells使用包含在胃癌细胞中表达的新表达序列标签的cDNA微阵列鉴定胃癌相关基因
Epithelial–Mesenchymal Transition Enhances Response to Oncolytic Herpesviral Therapy Through Nectin-1上皮-间质转化通过Nectin-1增强对溶瘤疱疹病毒治疗的反应

