Composition and Declassification in Possibilistic Information Flow Security
Datei | Beschreibung | Größe | Format | |
---|---|---|---|---|
00107822-1.pdf | 1.93 MB | Adobe PDF | Anzeigen |
Sonstige Titel: | Komposition und Deklassifikation in possibilistischer Informationsflusssicherheit | Autor/Autorin: | Bauereiß, Thomas ![]() |
BetreuerIn: | Hutter, Dieter | 1. GutachterIn: | Hutter, Dieter | Weitere Gutachter:innen: | Beckert, Bernhard | Zusammenfassung: | Formal methods for security can rule out whole classes of security vulnerabilities, but applying them in practice remains challenging. This thesis develops formal verification techniques for information flow security that combine the expressivity and scalability strengths of existing frameworks. It builds upon Bounded Deducibility (BD) Security, which allows specifying and verifying fine-grained policies about what information may flow when to whom. Our main technical result is a compositionality theorem for BD Security, providing scalability by allowing us to verify security properties of a large system by verifying smaller components. Its practical utility is illustrated by a case study of verifying confidentiality properties of a distributed social media platform. Moreover, we discuss its use for the modular development of secure workflow systems, and for the security-preserving enforcement of safety and security properties other than information flow control. |
Schlagwort: | information flow control; Bounded Deducibility; compositionality; formal verification; confidentiality; distributed social media platforms; workflow management systems; safety properties; separation of duty | Veröffentlichungsdatum: | 12-Sep-2019 | Dokumenttyp: | Dissertation | Zweitveröffentlichung: | no | URN: | urn:nbn:de:gbv:46-00107822-19 | Institution: | Universität Bremen | Fachbereich: | Fachbereich 03: Mathematik/Informatik (FB 03) |
Enthalten in den Sammlungen: | Dissertationen |
Seitenansichten
491
checked on 02.04.2025
Download(s)
199
checked on 02.04.2025
Google ScholarTM
Prüfe
Alle Ressourcen in diesem Repository sind urheberrechtlich geschützt.