Information flow control in object-oriented systems

1997 ◽  
Vol 9 (4) ◽  
pp. 524-538 ◽  
Author(s):  
P. Samarati ◽  
E. Bertino ◽  
A. Ciampichetti ◽  
S. Jajodia
1998 ◽  
Vol 1 (1) ◽  
pp. 26-65 ◽  
Author(s):  
Elisa Bertino ◽  
Sabrina De Capitani Di Vimercati ◽  
Elena Ferrari ◽  
Pierangela Samarati

Author(s):  
SHIH-CHIEN CHOU ◽  
YING-KAI WEN

Controlling information flows to prevent information leakage within an application is essential. According to the maturity of object-oriented techniques, many models were developed for the control in object-oriented systems. Since objects may be dynamically instantiated during program execution, controlling information flows among objects is difficult. Our research revealed that association is useful in the control. We developed an association-based information flow control model for object-oriented systems. It precisely controls information flows among objects through associations and constraints. It also offers features such as controlling method invocation through argument sensitivity, allowing declassification, allowing purpose-oriented method invocation, and precisely controlling write access. This paper proposes the model and the implementation of the model, which is composed of the language AbFlow (association-based flow) and its supporting environment.


Author(s):  
Allaoua Maamir ◽  
Abdelaziz Fellah

One of the main features of information flow control is to ensure the enforcement of privacy and regulated accessibility. However, most information flow models that have been proposed do not provide substantial assurance to enforce end-to-end confidentiality policies or they are too restrictive, overprotected, and inflexible. This paper presents an approach to control flow information in object-oriented systems using versions, thus allowing considerable flexibility without compromising system security by leaking sensitive information. Models based on message filtering intercept every message exchanged among objects to control the flow of information. Versions are proposed to provide flexibility and avoid unnecessary and undesirable blocking of messages during the filtering process. Two options of operations are supported by versions — cloning reply and non-cloning reply. Furthermore, we present an algorithm which enforces message filtering through these operations.


2015 ◽  
Vol 50 (9) ◽  
pp. 289-301 ◽  
Author(s):  
Pablo Buiras ◽  
Dimitrios Vytiniotis ◽  
Alejandro Russo

Sign in / Sign up

Export Citation Format

Share Document