Information flow in a distributed security setting
Ana Almeida Matos, Jan Cederquist

TL;DR
This paper explores how information flow security can be maintained in distributed systems with multiple local policies, introducing new security properties and enforcement mechanisms for programs with location-dependent behaviors.
Contribution
It introduces Distributed Non-disclosure and Flow Policy Confinement properties, along with enforcement techniques, to ensure compliance with local and allowed flow policies in distributed settings.
Findings
Type and effect systems effectively enforce security properties.
Hybrid static-dynamic mechanisms improve enforcement accuracy.
Distributed Non-Interference guarantees policy compliance in distributed systems.
Abstract
Information flow security is classically formulated in terms of the absence of illegal information flows, with respect to a security setting consisting of a single flow policy that specifies what information flows should be permitted in the system. In this paper we investigate the security issues that emerge in distributed security settings, where each computation domain establishes its own local security policy, and where programs may exhibit location-dependent behavior. In particular, we study the interplay between two distinct flow policy layers: the declared flow policy, established by the program itself, and the allowed flow policy, established externally to the program by each computation domain. We refine two security properties that articulate how the behaviors of programs comply to the respective flow policies: Distributed Non-disclosure, for enabling programs to declare…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSecurity and Verification in Computing · Advanced Malware Detection Techniques · Cloud Data Security Solutions
