Specifying and enforcing a fine-grained information flow policy : model and experiments


Autoria(s): Viet Triem Tong, Valérie; Clark, Andrew J.; Mé, Ludovic
Data(s)

2010

Resumo

In this paper we present a model for defining and enforcing a fine-grained information flow policy. We describe how the policy can be enforced on a typical computer and present experiments using the proposed model. A key feature of the model is that it allows the expression of rules which detail precisely which information elements are allowed to mix together. For example, the model allows the expression of a policy which forbids a doctor from mixing the personal medical details of the patients. The enforcement mechanisms tracks and records information flows within the system so that dynamic changes to the policy can be made with respect to information elements which may have propagated to different locations in the system.

Formato

application/pdf

Identificador

http://eprints.qut.edu.au/34086/

Relação

http://eprints.qut.edu.au/34086/1/34086.pdf

http://www.jowua.org/index.php/jowua

Viet Triem Tong, Valérie, Clark, Andrew J., & Mé, Ludovic (2010) Specifying and enforcing a fine-grained information flow policy : model and experiments. Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications, 1(1), pp. 56-71.

Direitos

Copyright 2010 Please consult the author.

Fonte

Computer Science; Faculty of Science and Technology; Information Security Institute

Palavras-Chave #080303 Computer System Security
Tipo

Journal Article