Automated Detection of Information Leakage in Access Control - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2007

Automated Detection of Information Leakage in Access Control

Résumé

The prevention of information flow is an important concern in several access control models. Even though this property is stated in the model specification, it is not easy to verify it in the actual implementation of a given security policy. In this paper we model-check rewrite-based implementations of access control policies. We propose a general algorithm that allows one to automatically identify information leakage. We apply our approach to the well-known security model of Bell and LaPadula and show that its generalization proposed by McLean does not protect a system against information leakage.
Fichier non déposé

Dates et versions

inria-00185713 , version 1 (06-11-2007)

Identifiants

  • HAL Id : inria-00185713 , version 1

Citer

Anderson Santana de Oliveira, Charles Morisset. Automated Detection of Information Leakage in Access Control. Second International Workshop on Security and Rewriting Techniques - SecReT 2007, Jun 2007, Paris, France. ⟨inria-00185713⟩
85 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More