Computability classes for enforcement mechanisms
Kevin W. Hamlen, Greg Morrisett, Fred B. Schneider · ACM Transactions on Programming Languages and Systems · 2006
A precise characterization of those security policies enforceable by program rewriting is given. This also exposes and rectifies problems in prior work, yielding a better characterization of those security policies enforceable by execution monitors as well as a taxonomy of enforceable security policies. Some but not all classes can be identified with known classes from computational complexity theory.