作者
Marco Avvenuti, Cinzia Bernardeschi, Nicoletta De Francesco
发表日期
2003/12/1
期刊
ACM SIGPLAN Notices
卷号
38
期号
12
页码范围
20-27
出版商
ACM
简介
Security of Java programs is important as they can be executed in different platforms. This paper addresses the problem of secure information flow for Java bytecode. In information flow analysis one wishes to check if high security data can ever propagate to low security observers. We propose a static analysis similar to the type-level abstract interpretation used for standard bytecode verification. Instead of types, our technique works with secrecy levels assigned to classes, methods' parameters and returned values, and handles implicit information flows. A verification tool based on the proposed technique is under development. Using the tool, programs downloaded from untrusted hosts can be checked locally prior to executing them.
引用总数
200420052006200720082009201020112012201320142015201620172018201920202021395744244321111
学术搜索中的文章
M Avvenuti, C Bernardeschi, N De Francesco - ACM SIGPLAN Notices, 2003