Privacy Assessment Using Static Taint Analysis (Tool Paper) - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2017

Privacy Assessment Using Static Taint Analysis (Tool Paper)

Résumé

When developing and maintaining distributed systems, auditing privacy properties gains more and more relevance. Nevertheless, this task is lacking support of automated tools and, hence, is mostly carried out manually. We present a formal approach which enables auditors to model the flow of critical data in order to shed new light on a system and to automatically verify given privacy constraints. The formalization is incorporated into a larger policy analysis and verification framework and overall soundness is proven with Isabelle/HOL. Using this solution, it becomes possible to automatically compute architectures which follow specified privacy conditions or to input an existing architecture for verification. Our tool is evaluated in two real-world case studies, where we uncover and fix previously unknown violations of privacy.
Fichier principal
Vignette du fichier
446833_1_En_16_Chapter.pdf (377.79 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01658424 , version 1 (07-12-2017)

Licence

Paternité

Identifiants

Citer

Marcel Von Maltitz, Cornelius Diekmann, Georg Carle. Privacy Assessment Using Static Taint Analysis (Tool Paper). 37th International Conference on Formal Techniques for Distributed Objects, Components, and Systems (FORTE), Jun 2017, Neuchâtel, Switzerland. pp.225-235, ⟨10.1007/978-3-319-60225-7_16⟩. ⟨hal-01658424⟩
491 Consultations
124 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More