Using equivalence relations for corrective enforcement of security policies

  • Authors:
  • Raphaël Khoury;Nadia Tawbi

  • Affiliations:
  • Department of Computer Science and Software Engineering, Laval University, Québec, QC, Canada;Department of Computer Science and Software Engineering, Laval University, Québec, QC, Canada

  • Venue:
  • MMM-ACNS'10 Proceedings of the 5th international conference on Mathematical methods, models and architectures for computer network security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we present a new framework of runtime security policy enforcement. Building on previous studies, we examine the enforcement power of monitors able to transform their target's execution, rather than simply accepting it if it is valid, or aborting it otherwise. We bound this ability by a restriction stating that any transformation must preserve equivalence between the monitor's input and output. We proceed by giving examples of meaningful equivalence relations and identify the security policies that are enforceable with their use. We also relate our work to previous findings in this field. Finally, we investigate how an a priori knowledge of the target program's behavior would increase the monitor's enforcement power.