Integration of XML streams in information flow analysis for Java

Arnaud Fontaine 1, 2
2 POPS - System and Networking for Portable Objects Proved to be Safe
LIFL - Laboratoire d'Informatique Fondamentale de Lille, Inria Lille - Nord Europe, IRCICA
Abstract : In this report we present an extension of an existing flow-sensitive analysis for secure information flow for Java bytecode that deals with flows of data from and to XML streams governed by an access control mechanism. Our approach consists in computing, at different program points, an abstract XML content graph (AXCG) which tracks data read from and written to XML streams relying on data tracked in the existing information flow analysis. The extension we propose to manage XML content is generic enough to permit connection with any role-based access control mechanism for XML. On the contrary to many information flow techniques, our approach does not require security levels to be known during the analysis: security aspects of information flow and access control mechanisms for XML are checked a posteriori with security levels either inferred from access control policies for XML streams, or given by the information flow policy for the rest of the program.
Liste complète des métadonnées

Littérature citée [31 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/inria-00511118
Contributeur : Arnaud Fontaine <>
Soumis le : lundi 23 août 2010 - 18:10:15
Dernière modification le : jeudi 11 janvier 2018 - 06:22:13
Document(s) archivé(s) le : mercredi 24 novembre 2010 - 03:02:18

Fichier

RT-0387.pdf
Fichiers produits par l'(les) auteur(s)

Identifiants

  • HAL Id : inria-00511118, version 1

Collections

Citation

Arnaud Fontaine. Integration of XML streams in information flow analysis for Java. [Technical Report] RT-0387, INRIA. 2010, pp.37. 〈inria-00511118〉

Partager

Métriques

Consultations de la notice

212

Téléchargements de fichiers

165