Skip to main content

Towards a General-Purpose Dynamic Information Flow Policy

Publication ,  Conference
Li, P; Zhang, D
Published in: Proceedings - IEEE Computer Security Foundations Symposium
January 1, 2022

Noninterference offers a rigorous end-to-end guarantee for secure propagation of information. However, real-world systems almost always involve security requirements that change during program execution, making noninterference inapplicable. Prior works alleviate the limitation to some extent, but even for a veteran in information flow security, understanding the subtleties in the syntax and semantics of each policy is challenging, largely due to very different policy specification languages, and more fundamentally, semantic requirements of each policy. We take a top-down approach and present a novel information flow policy, called Dynamic Release, which allows information flow restrictions to downgrade and upgrade in arbitrary ways. Dynamic Release is formalized on a novel framework that, for the first time, allows us to compare and contrast various dynamic policies in the literature. We show that Dynamic Release generalizes declassification, erasure, delegation and revocation. Moreover, it is the only dynamic policy that is both applicable and correct on a benchmark of tests with dynamic policy.

Duke Scholars

Published In

Proceedings - IEEE Computer Security Foundations Symposium

DOI

ISSN

1940-1434

Publication Date

January 1, 2022

Volume

2022-August

Start / End Page

260 / 275
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Li, P., & Zhang, D. (2022). Towards a General-Purpose Dynamic Information Flow Policy. In Proceedings - IEEE Computer Security Foundations Symposium (Vol. 2022-August, pp. 260–275). https://doi.org/10.1109/CSF54842.2022.9919639
Li, P., and D. Zhang. “Towards a General-Purpose Dynamic Information Flow Policy.” In Proceedings - IEEE Computer Security Foundations Symposium, 2022-August:260–75, 2022. https://doi.org/10.1109/CSF54842.2022.9919639.
Li P, Zhang D. Towards a General-Purpose Dynamic Information Flow Policy. In: Proceedings - IEEE Computer Security Foundations Symposium. 2022. p. 260–75.
Li, P., and D. Zhang. “Towards a General-Purpose Dynamic Information Flow Policy.” Proceedings - IEEE Computer Security Foundations Symposium, vol. 2022-August, 2022, pp. 260–75. Scopus, doi:10.1109/CSF54842.2022.9919639.
Li P, Zhang D. Towards a General-Purpose Dynamic Information Flow Policy. Proceedings - IEEE Computer Security Foundations Symposium. 2022. p. 260–275.

Published In

Proceedings - IEEE Computer Security Foundations Symposium

DOI

ISSN

1940-1434

Publication Date

January 1, 2022

Volume

2022-August

Start / End Page

260 / 275