Timing- and Termination-Sensitive Secure Information Flow: Exploring a New Approach | IEEE Conference Publication | IEEE Xplore

Timing- and Termination-Sensitive Secure Information Flow: Exploring a New Approach


Abstract:

Secure information flow guarantees the secrecy and integrity of data, preventing an attacker from learning secret information (secrecy) or injecting untrusted information...Show More

Abstract:

Secure information flow guarantees the secrecy and integrity of data, preventing an attacker from learning secret information (secrecy) or injecting untrusted information (integrity). Covert channels can be used to subvert these security guarantees, for example, timing and termination channels can, either intentionally or inadvertently, violate these guarantees by modifying the timing or termination behavior of a program based on secret or untrusted data. Attacks using these covert channels have been published and are known to work in practiceâ as techniques to prevent non-covert channels are becoming increasingly practical, covert channels are likely to become even more attractive for attackers to exploit. The goal of this paper is to understand the subtleties of timing and termination-sensitive noninterference, explore the space of possible strategies for enforcing noninterference guarantees, and formalize the exact guarantees that these strategies can enforce. As a result of this effort we create a novel strategy that provides stronger security guarantees than existing work, and we clarify claims in existing work about what guarantees can be made.
Date of Conference: 22-25 May 2011
Date Added to IEEE Xplore: 18 July 2011
ISBN Information:

ISSN Information:

Conference Location: Oakland, CA, USA

Contact IEEE to Subscribe

References

References is not available for this document.