PrivateFlow: decentralised information flow control in event based middleware

  • Authors:
  • I. Papagiannis;M. Migliavacca;P. Pietzuch;B. Shand;D. Eyers;J. Bacon

  • Affiliations:
  • Imperial College London;Imperial College London;Imperial College London;Clinical and Biomedical Computing Unit;University of Cambridge;University of Cambridge

  • Venue:
  • Proceedings of the Third ACM International Conference on Distributed Event-Based Systems
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Complex middleware frameworks are made out of interacting components which may include bugs. These frameworks are often extended to provide additional features by third-party extensions that may not be completely trusted and, as a result, compromise the security of the whole platform. Aiming to minimize these problems, we propose a demonstration of PrivateFlow, a publish/subscribe prototype supported by Decentralized Information Flow Control (DIFC). DIFC is a taint-tracking mechanism that can prevent components from leaking information. We will showcase a simple deployment of PrivateFlow that incorporates third-party untrusted components. In our demonstration, one of these components will try to leak sensitive information about the system's operation and it will fail once DIFC is activated.