Synthesizing Enforcement Monitors wrt. the Safety-Progress Classification of Properties - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue ICISS'08: International Conference on Information Systems Security Année : 2008

Synthesizing Enforcement Monitors wrt. the Safety-Progress Classification of Properties

Résumé

Runtime enforcement is a powerful technique to ensure that a program will respect a given security policy. We extend previous works on this topic in several directions. Firstly, we propose a generic notion of enforcement monitors based on a memory device and finite sets of control states and enforcement operations. Moreover, we specify their enforcement abilities w.r.t. the general safety-progress classification of properties. It allows a fine-grain characterization of the space of enforceable properties. Finally, we propose a systematic technique to produce an enforcement monitor from the Streett automaton recognizing a given safety, guarantee, obligation or response security property.
Fichier principal
Vignette du fichier
main.pdf (222.73 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00346063 , version 1 (11-12-2008)

Identifiants

  • HAL Id : hal-00346063 , version 1

Citer

Yliès Falcone, Jean-Claude Fernandez, Laurent Mounier. Synthesizing Enforcement Monitors wrt. the Safety-Progress Classification of Properties. ICISS'08: International Conference on Information Systems Security, 2008, pp.41-55. ⟨hal-00346063⟩
237 Consultations
199 Téléchargements

Partager

Gmail Facebook X LinkedIn More