A label-based information flow control model for object-oriented systems

被引:1
作者
Chou, Shih-Chien [1 ]
机构
[1] Natl Dong Hwa Univ, Dept Comp Sci & Informat Engn, Hualien 974, Taiwan
关键词
information security; access control; information leakage; information flow; information flow control; object-oriented system;
D O I
10.1080/02533839.2007.9671258
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
This paper proposes a label-based information flow control model to prevent information leakage within object-oriented systems. It offers the features of: (a) adapting to dynamic object state change, (b) adapting to dynamic role change, (c) preventing indirect information leakage, (d) detailing the control granularity to variables, (e) allowing purpose-oriented method invocation, (f) controlling method invocation through argument sensitivity, (g) allowing declassification, and (h) allowing only trusted sources to write a variable.
引用
收藏
页码:323 / 330
页数:8
相关论文
共 16 条
[1]  
[Anonymous], 1976, TECH REP
[2]  
[Anonymous], IEEE COMPUTER
[3]  
[Anonymous], 1993, IEEE Computer
[4]  
Bertsimas D., 1998, J FINANCIAL MARKETS, V1, P1, DOI DOI 10.1016/S1386-4181(97)00012-8
[5]   LATTICE MODEL OF SECURE INFORMATION-FLOW [J].
DENNING, DE .
COMMUNICATIONS OF THE ACM, 1976, 19 (05) :236-243
[6]   CERTIFICATION OF PROGRAMS FOR SECURE INFORMATION-FLOW [J].
DENNING, DE ;
DENNING, PJ .
COMMUNICATIONS OF THE ACM, 1977, 20 (07) :504-513
[7]  
Ford W., 2001, Secure Electronic Commerce
[8]   Information flow control in role-based model for distributed objects [J].
Izaki, K ;
Tanaka, K ;
Takizawa, M .
PROCEEDINGS OF THE EIGHTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, 2001, :363-370
[9]   Adding flexibility in information flow control for object-oriented systems using versions [J].
Maamir, A ;
Fellah, A .
INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2003, 13 (03) :313-325
[10]   MULTILEVEL SECURITY IN THE UNIX TRADITION [J].
MCILROY, MD ;
REEDS, JA .
SOFTWARE-PRACTICE & EXPERIENCE, 1992, 22 (08) :673-694