2018
DOI: 10.1007/978-3-030-02450-5_17
|View full text |Cite
|
Sign up to set email alerts
|

Using Theorem Provers to Increase the Precision of Dependence Analysis for Information Flow Control

Abstract: Information flow control (IFC) is a category of techniques for enforcing information flow properties. In this paper we present the Combined Approach, a novel IFC technique that combines a scalable system-dependence-graph-based (SDG-based) approach with a precise logic-based approach based on a theorem prover. The Combined Approach has an increased precision compared with the SDG-based approach on its own, without sacrificing its scalability. For every potential illegal information flow reported by the SDG-base… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
7
0

Year Published

2020
2020
2020
2020

Publication Types

Select...
1

Relationship

1
0

Authors

Journals

citations
Cited by 1 publication
(7 citation statements)
references
References 24 publications
(23 reference statements)
0
7
0
Order By: Relevance
“…This section presents the approaches in the Noninterference Framework. We present SDG-based approaches (using Herda et al [22]) in Section 3.1, logicbased approaches (using previous works [6,21]) in Section 3.2, and automatic test generation based on symbolic execution (using Herda et al [21]) in Section 3.3.…”
Section: Approaches Of the Noninterference Frameworkmentioning
confidence: 99%
See 4 more Smart Citations
“…This section presents the approaches in the Noninterference Framework. We present SDG-based approaches (using Herda et al [22]) in Section 3.1, logicbased approaches (using previous works [6,21]) in Section 3.2, and automatic test generation based on symbolic execution (using Herda et al [21]) in Section 3.3.…”
Section: Approaches Of the Noninterference Frameworkmentioning
confidence: 99%
“…In this article, we present an overview of recent combinations [6,21,22] of deductive program verification with automatic test generation on the one hand and static analysis on the other hand, with the goal of checking noninterference. The resulting Noninterference Framework can be used both for proving that a given program fulfills a given noninterference property and, also, for finding a counterexample that demonstrates a noninterference violation in case the noninterference property is not fulfilled.…”
Section: Introductionmentioning
confidence: 99%
See 3 more Smart Citations