Practical, Flexible programming with Information Flow Control

ITF
Broberg, Niklas
2011-08-15T11:01:24Z
2011-08-15T11:01:24Z
2011-08-15
Mainstream mechanisms for protection of information security are not adequate. Most vulnerabilities today do not arise from deficiencies in network security or encryption mechanisms, but from software that fails to provide adequate protection for the information it handles. Programs are not prevented from revealing too much of their information to actors who can legitimately interact with them, and restricting access to the data is not a viable solution. What is needed is mechanisms that can control not only what information a program has access to, but also how the program handles that information once access is given. This thesis describes Paralocks, a language for building expressive but statically verifiable fine-grained information flow policies, and Paragon, an extension of Java supporting the enforcement of Paralocks policy specifications. Our contributions can be categorised along three axes: * The design of a policy specification language, Paralocks, that is expressive enough to model a large number of different mechanisms for information flow control. *The development of a formal semantic information flow model for Paralocks that can be used to prove properties about programs and enforcement mechanisms. * The development of Paragon, an extension of Java with support for enforcement of Paralocks information flow policies. Together these components provide a complete framework for programming with information flow control. It is the first framework to bring together all aspects of information flow control including dynamically changing policies such as declassification, making it both theoretically sound as well as usable for solving practical programming problems.sv
2011-08-30
Tisdagen den 30 augusti 2011, kl. 10.00, Hörsal HB4, Hörsalsvägen 8, Chalmers tekniska högskolasv
Department of Computer Science and Engineering ; Institutionen för data- och informationstekniksv
ITF
niklas.broberg@chalmers.sesv
Göteborgs universitet. IT-fakultetensv
0346-718X
http://hdl.handle.net/2077/26534
engsv
Computer securitysv
Programming languagessv
Practical, Flexible programming with Information Flow Controlsv
Text
Doctor of Philosophysv
Doctoral thesis

Files

Original bundle

Now showing 1 - 2 of 2
Loading...
Thumbnail Image
Name:
gupea_2077_26534_1.pdf
Size:
1.3 MB
Format:
Adobe Portable Document Format
Description:
Thesis
Loading...
Thumbnail Image
Name:
gupea_2077_26534_2.pdf
Size:
53.05 KB
Format:
Adobe Portable Document Format
Description:
Defence information and abstract

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
gupea_2077_26534_3.txt
Size:
4.68 KB
Format:
Item-specific license agreed upon to submission
Description: