The Compositional Security Checker: A Tool for the Verification of Information Flow Security Properties

  • Authors:
  • R. Focardi;R. Gorrieri

  • Affiliations:
  • -;-

  • Venue:
  • The Compositional Security Checker: A Tool for the Verification of Information Flow Security Properties
  • Year:
  • 1996

Quantified Score

Hi-index 0.00

Visualization

Abstract

The Compositional Security Checker (CoSeC for short) is a semantic-based tool for the automatic verification of some compositional information flow properties. The specifications given as inputs to CoSeC are terms of the Security Process Algebra, a language suited for the specification of concurrent systems where actions belong to two different levels of confidentiality. The information flow security properties which can be verified by CoSeC are some of those classified in [FoGoJCS]. They are derivations of some classic notions, e.g. Non Interference. The tool is based on the same architecture of the Concurrency Workbench, from which some modules have been integrally imported. The usefulness of the tool is tested with the significative case-study of an access-monitor, presented in several versions in order to illustrate the relative merits of the various information flow properties that CoSeC can check.