DocumentCode :
1764909
Title :
Hybrid Static-Runtime Information Flow and Declassification Enforcement
Author :
Rocha, Bruno P. S. ; Conti, Marco ; Etalle, S. ; Crispo, B.
Author_Institution :
Eindhoven Univ. of Technol., Eindhoven, Netherlands
Volume :
8
Issue :
8
fYear :
2013
fDate :
Aug. 2013
Firstpage :
1294
Lastpage :
1305
Abstract :
There are different paradigms for enforcing information flow and declassification policies. These approaches can be divided into static analyzers and runtime enforcers. Each class has its own strengths and weaknesses, each being able to enforce a different set of policies. In this paper, we introduce a hybrid static-runtime enforcement mechanism that works on unannotated program code and supports information-flow control, as well as declassification policies. Our approach manages to enforce realistic policies, as shown by our three running examples, all within the context of a mobile device application, which cannot be handled separately by static or runtime approaches, and are also not covered by current access control models of mobile platforms such as Android or iOS. We also show that including an intermediate step (called preload check) makes both the static analysis system independent (in terms of security labels) and the runtime enforcer lightweight. Finally, we implement our runtime enforcer and run experiments that show that its overhead is so low that the approach can be rolled out on current mobile systems.
Keywords :
operating system kernels; security of data; Android; access control model; declassification enforcement; declassification policy; hybrid static runtime enforcement mechanism; hybrid static runtime information flow; iOS; information flow control; information flow enforcement; mobile device application; mobile platform; mobile system; realistic policy; runtime enforcer lightweight; runtime enforcers; static analysis system; static analyzers; unannotated program code; Mobile communication; Monitoring; Remuneration; Runtime; Security; Smart phones; Data security; information security;
fLanguage :
English
Journal_Title :
Information Forensics and Security, IEEE Transactions on
Publisher :
ieee
ISSN :
1556-6013
Type :
jour
DOI :
10.1109/TIFS.2013.2267798
Filename :
6530623
Link To Document :
بازگشت