Action systems for security specification
Jane E. Sinclair · Journal of Computer Security · 1997
To be generally useful a theory must be both theoretically sound and practically applicable. We consider the noninterference approach to security specification, focusing in particular on Roscoe's work on nondeterminism. This provides a starting point