Programmable enforcement framework of information flow policies.

Minh Ngo, Fabio Massacci · 2014

Abstract. We propose a programmable framework that can be eas-ily instantiated to enforce a large variety of information flow proper-ties. Our framework is based on the idea of secure multi-execution in which multiple instances of the controlled program are executed in par-allel. The information flow property of choice can be obtained by sim-ply implementing programs that control parallel executions. We present the architecture of the enforcement mechanism and its instantiations for non-interference (NI) (from Devriese and Piessens), non-deducibility (ND) (from Sutherland) and some properties proposed by Mantel, such as removal of inputs (RI) and deletion of inputs (DI), and demonstrate formally soundness and precision of enforcement for these properties.

Read the paper · More papers on PaperTik