• Title of article

    Language-based information-flow security

  • Author/Authors

    A.، Sabelfeld, نويسنده , , A.C.، Myers, نويسنده ,

  • Issue Information
    روزنامه با شماره پیاپی سال 2003
  • Pages
    -4
  • From page
    5
  • To page
    0
  • Abstract
    Current standard security practices do not provide substantial assurance that the end-to-end behavior of a computing system satisfies important security policies such as confidentiality. An end-to-end confidentiality policy might assert that secret input data cannot be inferred by an attacker through the attackerʹs observations of system output; this policy regulates information flow. Conventional security mechanisms such as access control and encryption do not directly address the enforcement of information-flow policies. Previously, a promising new approach has been developed: the use of programming-language techniques for specifying and enforcing information-flow policies. In this paper, we survey the past three decades of research on information-flow security, particularly focusing on work that uses static program analysis to enforce information-flow policies. We give a structured view of work in the area and identify some important open challenges.
  • Journal title
    IEEE Journal on Selected Areas in Communications
  • Serial Year
    2003
  • Journal title
    IEEE Journal on Selected Areas in Communications
  • Record number

    60859