首页> 外文会议>International Conference on Secure Software Integration and Reliability Improvement >A Practical Covert Channel Identification Approach in Source Code Based on Directed Information Flow Graph
【24h】

A Practical Covert Channel Identification Approach in Source Code Based on Directed Information Flow Graph

机译:基于定向信息流图的源代码中的实用隐蔽信道识别方法

获取原文

摘要

Covert channel analysis is an important requirement when building secure information systems, and identification is the most difficult task. Although some approaches were presented, they are either experimental or constrained to some particular systems. This paper presents a practical approach based on directed information flow graph taking advantage of the source code analysis. The approach divides the whole system into serval independent modules and analyzes them respectively. All the shared variables and their caller functions are found out from the source codes and modeled into directed information flow graphs. When the information flow branches are visible and modifiable to the external interface, a potential covert channel exists. Contributions made in this paper are as follows: a modularized analysis scheme is proved and reduces the workloads of identifying, a directed information flow graph algorithm is presented and used to model the covert channels, more than 30 covert channels have been identified in Linux kernel source code using this scheme, and a typical channel scenario is constructed.
机译:隐蔽频道分析是建立安全信息系统时的重要要求,识别是最困难的任务。虽然呈现了一些方法,但它们是实验性的或限制某些特定系统。本文介绍了利用源代码分析的定向信息流图的实用方法。该方法将整个系统划分为Serval独立模块并分别分析它们。所有共享变量及其来电者功能都从源代码中找到,并建模到导向信息流图。当信息流分支是可见的并且可修改到外部接口时,存在潜在的隐蔽信道。在本文中作出了贡献如下:一模块化分析方案证明,并减少识别,有向信息流图算法,以及用于将隐蔽信道模型的工作负荷,超过30个隐蔽信道已经在Linux内核源识别使用此方案的代码和典型的频道方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号