Runtime enforcement of information flow security in tree manipulating processes

Máté Kovács, Helmut Seidl

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

We consider the problem of enforcing information flow policies in Xml manipulating programs such as Web services and business processes implemented in current workflow languages. We propose a runtime monitor that can enforce the secrecy of freely chosen subtrees of the data throughout the execution. The key idea is to apply a generalized constant propagation for computing the public effect of branching constructs whose conditions may depend on the secret. This allows for a better precision than runtime monitors which rely on tainting of variables or nodes alone. We demonstrate our approach for a minimalistic tree manipulating programming language and prove its correctness w.r.t. the concrete semantics of programs.

Original languageEnglish
Title of host publicationEngineering Secure Software and Systems - 4th International Symposium, ESSoS 2012, Proceedings
Pages46-59
Number of pages14
DOIs
StatePublished - 2012
Event4th International Symposium on Engineering Secure Software and Systems, ESSoS 2012 - Eindhoven, Netherlands
Duration: 16 Feb 201217 Feb 2012

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7159 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference4th International Symposium on Engineering Secure Software and Systems, ESSoS 2012
Country/TerritoryNetherlands
CityEindhoven
Period16/02/1217/02/12

Keywords

  • Semi-structured data
  • information flow control
  • runtime enforcement

Fingerprint

Dive into the research topics of 'Runtime enforcement of information flow security in tree manipulating processes'. Together they form a unique fingerprint.

Cite this