作者
Wes Masri, Andy Podgurski, David Leon
发表日期
2004/11/2
研讨会论文
15th International Symposium on Software Reliability Engineering
页码范围
198-209
出版商
IEEE
简介
A new approach to dynamic information flow analysis is presented that can be used to detect and debug insecure flows in programs. It can be applied offline to validate and debug a program against an information flow policy, or, when fast response is not critical, it can be applied online to prevent illegal flows in deployed programs. Since dynamic analysis alone is inherently unable to detect implicit information flows, our approach incorporates a static preprocessing phase that permits detection of most implicit flows at runtime, in addition to explicit ones. To support interactive debugging of insecure flows, it also incorporates a new forward computing algorithm for dynamic slicing, which is more precise than previous forward computing algorithms and is not restricted to programs with structured control flow. A prototype tool implementing the proposed approach has been developed for Java byte code programs. Case …
引用总数
200320042005200620072008200920102011201220132014201520162017201820192020202120222023202415481410845184762346461
学术搜索中的文章
W Masri, A Podgurski, D Leon - 15th International Symposium on Software Reliability …, 2004