Towards a General-Purpose Dynamic Information Flow Policy

Peixuan Li, Danfeng Zhang

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Noninterference offers a rigorous end-to-end guarantee for secure propagation of information. However, real-world systems almost always involve security requirements that change during program execution, making noninterference inapplicable. Prior works alleviate the limitation to some extent, but even for a veteran in information flow security, understanding the subtleties in the syntax and semantics of each policy is challenging, largely due to very different policy specification languages, and more fundamentally, semantic requirements of each policy. We take a top-down approach and present a novel information flow policy, called Dynamic Release, which allows information flow restrictions to downgrade and upgrade in arbitrary ways. Dynamic Release is formalized on a novel framework that, for the first time, allows us to compare and contrast various dynamic policies in the literature. We show that Dynamic Release generalizes declassification, erasure, delegation and revocation. Moreover, it is the only dynamic policy that is both applicable and correct on a benchmark of tests with dynamic policy.

Original languageEnglish (US)
Title of host publicationProceedings - 2022 IEEE 35th Computer Security Foundations Symposium, CSF 2022
PublisherIEEE Computer Society
Pages260-275
Number of pages16
ISBN (Electronic)9781665484176
DOIs
StatePublished - 2022
Event35th IEEE Computer Security Foundations Symposium, CSF 2022 - Haifa, Israel
Duration: Aug 7 2022Aug 10 2022

Publication series

NameProceedings - IEEE Computer Security Foundations Symposium
Volume2022-August
ISSN (Print)1940-1434

Conference

Conference35th IEEE Computer Security Foundations Symposium, CSF 2022
Country/TerritoryIsrael
CityHaifa
Period8/7/228/10/22

All Science Journal Classification (ASJC) codes

  • General Engineering

Fingerprint

Dive into the research topics of 'Towards a General-Purpose Dynamic Information Flow Policy'. Together they form a unique fingerprint.

Cite this