Matches in SemOpenAlex for { <https://semopenalex.org/work/W76754017> ?p ?o ?g. }
- W76754017 abstract "This thesis provides means to achieve end-to-end information-flow security in interactive systems. The elusiveness of this problem stems from the fact that interaction patterns, primitives, synchronous communication and nondeterminism combine in ways where seemingly innocuous systems compromise security in unexpected ways under interaction.We study what it means for interactive systems to not leak information about confidential behavior into observable behavior in a nondeterministic setting. We focus on two properties: progress-sensitive noninterference (PSNI), requiring that observable behavior is invariant to confidential input, and progress-insensitive noninterference (PINI), permitting confidential input to impede the ability of a system to make progress on its observable output. The latter is a popular target of information-flow security enforcement mechanisms, e.g. JSFlow, Paragon, LIO and Jif. We formalize PINI and PSNI extensionally, based on the view the attacker has on the interaction. To identify the essense of interactive systems security, we explore classes of attacks PSNI and PINI must guarantee protection against, and find previous work ignores classes of attacks powered by varied presence of input -- a high-bandwidth channel in the concurrent setting. This is due to limitations in the model used for system environments.To address this, we devise a new, preservation-based, formalization of noninterference. Since preservation-based noninterference guarantees secure systems interact securely, it is compositional; we prove this for a core of combinators, and derive from it a rich language of security-preserving combinators. While both PSNI and PINI are preserved under arbitrary wirings, the latter is not preserved fairly; it relies fundamentally on lack of scheduling fairness to guarantee security of interactions, and is therefore unfit autonomous interactive systems security.To facilitate building secure systems in parts, we advance secure multi-execution (SME): a combinator which repairs insecurities. SME thus makes any interactive system, secure or not, readily pluggable into a secure composed system. We prove soundness for all fair schedulers, and redesign SME to enforce PSNI, obtaining a more semantics-preserving combinator. We give a language-independent model for information release in SME. For scenarios where semantics must be preserved, we present type-based enforcements of PSNI and PINI. The type systems guarantee absence of leaks through challenging constructs e.g. dynamic event handlers and lazy class initialization. Lastly, we give a combinator which places a logarithmic bound on leaks through progress. Together with the type-based enforcement of PINI, we get a permissive hybrid enforcement of a stronger property." @default.
- W76754017 created "2016-06-24" @default.
- W76754017 creator A5086787088 @default.
- W76754017 date "2014-01-01" @default.
- W76754017 modified "2023-10-16" @default.
- W76754017 title "Securing Interactive Systems" @default.
- W76754017 cites W105715719 @default.
- W76754017 cites W1265250368 @default.
- W76754017 cites W1431138 @default.
- W76754017 cites W1498342204 @default.
- W76754017 cites W1499226144 @default.
- W76754017 cites W1501479749 @default.
- W76754017 cites W1541615208 @default.
- W76754017 cites W1547562281 @default.
- W76754017 cites W1553595881 @default.
- W76754017 cites W1569728954 @default.
- W76754017 cites W1572388405 @default.
- W76754017 cites W1597755753 @default.
- W76754017 cites W1603844035 @default.
- W76754017 cites W1857247180 @default.
- W76754017 cites W1882297107 @default.
- W76754017 cites W1940060540 @default.
- W76754017 cites W1961998804 @default.
- W76754017 cites W1977764760 @default.
- W76754017 cites W1983142587 @default.
- W76754017 cites W1997775274 @default.
- W76754017 cites W1997988349 @default.
- W76754017 cites W2005525408 @default.
- W76754017 cites W2008332764 @default.
- W76754017 cites W2016604944 @default.
- W76754017 cites W2023931614 @default.
- W76754017 cites W2027146564 @default.
- W76754017 cites W2034527657 @default.
- W76754017 cites W2046381502 @default.
- W76754017 cites W2049440551 @default.
- W76754017 cites W2069858199 @default.
- W76754017 cites W2071700915 @default.
- W76754017 cites W2072794470 @default.
- W76754017 cites W2079512738 @default.
- W76754017 cites W2094873755 @default.
- W76754017 cites W2095762545 @default.
- W76754017 cites W2096412050 @default.
- W76754017 cites W2097744609 @default.
- W76754017 cites W2097833793 @default.
- W76754017 cites W2098820900 @default.
- W76754017 cites W2101678831 @default.
- W76754017 cites W2103428609 @default.
- W76754017 cites W2110904621 @default.
- W76754017 cites W2111794592 @default.
- W76754017 cites W2113660296 @default.
- W76754017 cites W2116807588 @default.
- W76754017 cites W2117320004 @default.
- W76754017 cites W2121029475 @default.
- W76754017 cites W2121043258 @default.
- W76754017 cites W2123858370 @default.
- W76754017 cites W2128282420 @default.
- W76754017 cites W2130207003 @default.
- W76754017 cites W2132699727 @default.
- W76754017 cites W2134296086 @default.
- W76754017 cites W2136887296 @default.
- W76754017 cites W2136898254 @default.
- W76754017 cites W2139289463 @default.
- W76754017 cites W2141126977 @default.
- W76754017 cites W2141535462 @default.
- W76754017 cites W2145846275 @default.
- W76754017 cites W2149854126 @default.
- W76754017 cites W2158126684 @default.
- W76754017 cites W2158196184 @default.
- W76754017 cites W2162755110 @default.
- W76754017 cites W2162785273 @default.
- W76754017 cites W2167004108 @default.
- W76754017 cites W2168686464 @default.
- W76754017 cites W2168753065 @default.
- W76754017 cites W2296605318 @default.
- W76754017 cites W2340406763 @default.
- W76754017 cites W2523797613 @default.
- W76754017 cites W2970349335 @default.
- W76754017 cites W3139756671 @default.
- W76754017 cites W34782372 @default.
- W76754017 cites W50887981 @default.
- W76754017 cites W54762625 @default.
- W76754017 cites W2181492671 @default.
- W76754017 hasPublicationYear "2014" @default.
- W76754017 type Work @default.
- W76754017 sameAs 76754017 @default.
- W76754017 citedByCount "1" @default.
- W76754017 countsByYear W767540172015 @default.
- W76754017 crossrefType "dissertation" @default.
- W76754017 hasAuthorship W76754017A5086787088 @default.
- W76754017 hasConcept C103377522 @default.
- W76754017 hasConcept C111919701 @default.
- W76754017 hasConcept C138885662 @default.
- W76754017 hasConcept C176181172 @default.
- W76754017 hasConcept C184842701 @default.
- W76754017 hasConcept C199360897 @default.
- W76754017 hasConcept C2779136372 @default.
- W76754017 hasConcept C29024540 @default.
- W76754017 hasConcept C38652104 @default.
- W76754017 hasConcept C41008148 @default.
- W76754017 hasConcept C41895202 @default.