Software Practice and Experience · 2004 · 15 citations · 24 references
EngineeringInformation SecurityVerificationSource Code AnalysisFormal VerificationSoftware AnalysisJava BytecodeSecure Information FlowBinary AnalysisStatic CheckingCode TransformationMultilevel Security PolicyComputer ScienceStatic Program AnalysisLanguage-based SecurityData SecurityCryptographySoftware SecurityProgram AnalysisFormal Methods
Abstract A method is presented for checking secure information flow in Java bytecode, assuming a multilevel security policy that assigns security levels to the objects. The method exploits the type‐level abstract interpretation of standard bytecode verification to detect illegal information flows. We define an algorithm transforming the original code into another code in such a way that a typing error detected by the Verifier on the transformed code corresponds to a possible illicit information flow in the original code. We present a prototype tool that implements the method and we show an example of application. Copyright © 2004 John Wiley & Sons, Ltd.
24
Security Policies and Security Models
Joseph A. Goguen, José Meseguer · 1982 · 2.1K citations
A lattice model of secure information flow
Dorothy E. Denning · Communications of the ACM · 1976 · 1.9K citations · Full text
Andrew C. Myers · 1999 · 1K citations · Full text