Title of article
Language-based information-flow security
Author/Authors
A.، Sabelfeld, نويسنده , , A.C.، Myers, نويسنده ,
Issue Information
روزنامه با شماره پیاپی سال 2003
Pages
-4
From page
5
To page
0
Abstract
Current standard security practices do not provide substantial assurance that the end-to-end behavior of a computing system satisfies important security policies such as confidentiality. An end-to-end confidentiality policy might assert that secret input data cannot be inferred by an attacker through the attackerʹs observations of system output; this policy regulates information flow. Conventional security mechanisms such as access control and encryption do not directly address the enforcement of information-flow policies. Previously, a promising new approach has been developed: the use of programming-language techniques for specifying and enforcing information-flow policies. In this paper, we survey the past three decades of research on information-flow security, particularly focusing on work that uses static program analysis to enforce information-flow policies. We give a structured view of work in the area and identify some important open challenges.
Journal title
IEEE Journal on Selected Areas in Communications
Serial Year
2003
Journal title
IEEE Journal on Selected Areas in Communications
Record number
60859
Link To Document