Probabilistic aspects: checking security in an imperfect world

  • Authors:
  • Chris Hankin;Flemming Nielson;Hanne Riis Nielson

  • Affiliations:
  • Department of Computing, Imperial College London;DTU Informatics, Technical University of Denmark;DTU Informatics, Technical University of Denmark

  • Venue:
  • TGC'10 Proceedings of the 5th international conference on Trustworthly global computing
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

We address the challenges arising from enforcing security policies in an imperfect world - in a system involving humans, a determined attacker always has a chance of circumventing any security. We motivate our approach by two examples: an on-line auction house; and a airport security system. In our work, security policies are enforced using a probabilistic aspect-oriented approach; policies are combined using a rich set of policy composition operators. We present the examples using a process-based language in which processes and local data are distributed across a number of locations (network addresses). The formal definition of the language gives rise to Markov Decision Processes.