inria-00511118, version 1
Integration of XML streams in information flow analysis for Java
N° RT-0387 (2010)
Résumé : In this report we present an extension of an existing flow-sensitive analysis for secure information flow for Java bytecode that deals with flows of data from and to XML streams governed by an access control mechanism. Our approach consists in computing, at different program points, an abstract XML content graph (AXCG) which tracks data read from and written to XML streams relying on data tracked in the existing information flow analysis. The extension we propose to manage XML content is generic enough to permit connection with any role-based access control mechanism for XML. On the contrary to many information flow techniques, our approach does not require security levels to be known during the analysis: security aspects of information flow and access control mechanisms for XML are checked a posteriori with security levels either inferred from access control policies for XML streams, or given by the information flow policy for the rest of the program.
- 1 : Laboratoire d'Informatique Fondamentale de Lille (LIFL)
- CNRS : UMR8022 – INRIA – IRCICA – Université Lille 1 - Sciences et Technologies
- 2 : POPS (INRIA Lille - Nord Europe)
- INRIA – CNRS : UMR8022 – Université Lille 1 - Sciences et Technologies – IRCICA
- Domaine : Informatique/Informatique ubiquitaire
Informatique/Systèmes embarqués
Informatique/Logique en informatique
Informatique/Cryptographie et sécurité - Référence interne : RT-0387
- inria-00511118, version 1
- http://hal.inria.fr/inria-00511118
- oai:hal.inria.fr:inria-00511118
- Contributeur : Arnaud Fontaine
- Soumis le : Lundi 23 Août 2010, 18:10:15
- Dernière modification le : Jeudi 16 Juin 2011, 09:36:19







Documents associés
Exporter