首页> 外文期刊>International Journal of Information Security >Instruction-level security typing by abstract interpretation
【24h】

Instruction-level security typing by abstract interpretation

机译:通过抽象解释进行指令级安全性键入

获取原文
获取原文并翻译 | 示例
           

摘要

We present a method based on abstract interpretation to check secure information flow in programs with dynamic structures where input and output channels are associated with security levels. In the concrete operational semantics each value is annotated by a security level dynamically taking into account both the explicit and the implicit information flows. We define a collecting semantics which associates with each program point the set of concrete states of the machine when the point is reached. The abstract domains are obtained from the concrete ones by keeping the security levels and forgetting the actual values. Using this framework, we define an abstract semantics, called instruction-level security typing, that allows us to certify a larger set of programs with respect to the typing approaches to check secure information flow. An efficient implementation is shown, operating a fixpoint iteration similar to that of the Java bytecode verification.
机译:我们提出一种基于抽象解释的方法,以检查具有动态结构的程序中的安全信息流,其中输入和输出通道与安全级别相关联。在具体的操作语义中,每个值都由安全级别动态地注释,同时考虑了显式和隐式信息流。我们定义了一个收集语义,当到达每个程序点时,该语义与每个程序点相关联。通过保持安全级别并忘记实际值,可以从具体域中获取抽象域。使用此框架,我们定义了一种抽象的语义,称为指令级安全类型,它使我们可以根据类型检查方法来验证更大的程序集,以检查安全信息流。显示了一种有效的实现,该实现的操作类似于Java字节码验证的定点迭代。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号