English
 
Help Privacy Policy Disclaimer
  Advanced SearchBrowse

Item

ITEM ACTIONSEXPORT
  From Fine- to Coarse-Grained Dynamic Information Flow Control and Back, a Tutorial on Dynamic Information Flow

Vassena, M., Russo, A., Garg, D., Rajani, V., & Stefan, D. (2022). From Fine- to Coarse-Grained Dynamic Information Flow Control and Back, a Tutorial on Dynamic Information Flow. Retrieved from https://arxiv.org/abs/2208.13560.

Item is

Files

show Files
hide Files
:
arXiv:2208.13560.pdf (Any fulltext), 951KB
Name:
arXiv:2208.13560.pdf
Description:
File downloaded from arXiv at 2022-12-05 12:44
OA-Status:
Not specified
Visibility:
Public
MIME-Type / Checksum:
application/pdf / [MD5]
Technical Metadata:
Copyright Date:
-
Copyright Info:
-

Locators

show

Creators

show
hide
 Creators:
Vassena, Marco1, Author
Russo, Alejandro1, Author
Garg, Deepak2, Author           
Rajani, Vineet1, Author
Stefan, Deian1, Author
Affiliations:
1External Organizations, ou_persistent22              
2Group D. Garg, Max Planck Institute for Software Systems, Max Planck Society, ou_2105289              

Content

show
hide
Free keywords: Computer Science, Programming Languages, cs.PL,Computer Science, Cryptography and Security, cs.CR
 Abstract: This tutorial provides a complete and homogeneous account of the latest
advances in fine- and coarse-grained dynamic information-flow control (IFC)
security. Since the 70s, the programming language and the operating system
communities have proposed different IFC approaches. IFC operating systems track
information flows in a coarse-grained fashion, at the granularity of a process.
In contrast, traditional language-based approaches to IFC are fine-grained:
they track information flows at the granularity of program variables. For
decades, researchers believed coarse-grained IFC to be strictly less permissive
than fine-grained IFC -- coarse-grained IFC systems seem inherently less
precise because they track less information -- and so granularity appeared to
be a fundamental feature of IFC systems. We show that the granularity of the
tracking system does not fundamentally restrict how precise or permissive
dynamic IFC systems can be. To this end, we mechanize two mostly standard
languages, one with a fine-grained dynamic IFC system and the other with a
coarse-grained dynamic IFC system, and prove a semantics-preserving translation
from each language to the other. In addition, we derive the standard security
property of non-interference of each language from that of the other via our
verified translation. These translations stand to have important implications
on the usability of IFC approaches. The coarse- to fine-grained direction can
be used to remove the label annotation burden that fine-grained systems impose
on developers, while the fine- to coarse-grained translation shows that
coarse-grained systems -- which are easier to design and implement -- can track
information as precisely as fine-grained systems and provides an algorithm for
automatically retrofitting legacy applications to run on existing
coarse-grained systems.

Details

show
hide
Language(s): eng - English
 Dates: 2022-08-292022
 Publication Status: Published online
 Pages: 122 p.
 Publishing info: -
 Table of Contents: -
 Rev. Type: -
 Identifiers: arXiv: 2208.13560
URI: https://arxiv.org/abs/2208.13560
BibTex Citekey: Vassena2208.13560
 Degree: -

Event

show

Legal Case

show

Project information

show

Source

show