loading...
Detecting and Debugging Insecure Information Flows
Saint-Malo, Bretagne, France November 02-November 05
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ISSRE.2004.1715th International Symposium on Softw ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Wes Masri, Case Western Reserve University, Cleveland, OH
Andy Podgurski, Case Western Reserve University, Cleveland, OH
David Leon, Case Western Reserve University, Cleveland, OH
A new approach to dynamic information flow analysis is presented that can be used to detect and debug insecure flows in programs. It can be applied offline to validate and debug a program against an information flow policy, or, when fast response is not critical, it can be applied online to prevent illegal flows in deployed programs. Since dynamic analysis alone is inherently unable to detect implicit information flows, our approach incorporates a static preprocessing phase that permits detection of most implicit flows at runtime, in addition to explicit ones. To support interactive debugging of insecure flows, it also incorporates a new forward computing algorithm for dynamic slicing, which is more precise than previous forward computing algorithms and is not restricted to programs with structured control flow. A prototype tool implementing the proposed approach has been developed for Java byte code programs. Case studies in which this tool was applied to several subject programs are described.
Citation:
Wes Masri, Andy Podgurski, David Leon, "Detecting and Debugging Insecure Information Flows," issre, pp.198-209, 15th International Symposium on Software Reliability Engineering (ISSRE'04), 2004
Usage of this product signifies your acceptance of the Terms of Use.