Language-based information-flow security
Explore this paper's citation graph
Summary
A structured view of research on information-flow security is given, particularly focusing on work that uses static program analysis to enforce information- flow policies, and some important open challenges are identified.
- Type
- article
- Published
- 2003-01-14
- Cited by
- 2,238
- References
- 150
- Access
- Open access
- OpenAlex
- https://openalex.org/W2122049982
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:818454
Keywords
Computer science, Computer security, Information flow, Security policy, Confidentiality
References
- Compiling with Types
- Book review: A Theory of Objects by Martin Abadi and Luca Cardelli (Springer-Verlag, 1996): Series--Monographs in Computer Science
- End-to-end arguments in system design
- Bisimulation through Probabilistic Testing
- Simple Object Access Protocol と,その応用としてのソフトウェアの組み合わせについて (渡邉昭夫教授退任記念号)
- Simple object access protocol (SOAP) 1.1
- Trust and Dependence Analysis
- An information flow tool for Gypsy
- A Per Model of Secure Information Flow in Sequential Programs
- Semantic Models for the Security of Sequential and Concurrent Programs
- Secure Information Flow via Linear Continuations
- A unifying approach to the security of distributed and multi-threaded programs
- A Theory of Objects
- Principles of Program Analysis
- A Calculus for Cryptographic Protocols: The spi Calculus
- Trust in the lambda-Calculus
- Programming Languages for Information Security
- Type Based Techniques for Covert Channel Elimination and Register Allocation
- Static analysis and computer security: new techniques for software assurance
- Secure composition of untrusted code: box π, wrappers, and causality types
Cited by
- Observation-based Fine Grained Access Control for Relational Databases
- Dynamic Information Flow Analysis for JavaScript in a Web Browser
- A Framework for the Cryptographic Verification of Java-Like Programs
- LMonad: Information flow control for Haskell web applications
- Challenges for Information-flow Security
- Influence: A Quantitative Approach for Data Integrity (CMU-CyLab-08-005)
- From Interfering to Non-interfering Programs
- Structuring structural operational semantics
- Probability and Time in Measuring Security
- An MSLS-EMM for enforcing confidentiality in malicious environments
- Using functional active objects to enforce privacy
- Domain Separation by Construction
- HiPIP: High-Performance Invocation Protection
- Security analysis of private data enquiries in Erlang
- Secure Data Preservers for Web Services
- Language based information routing security: policy enforcement
- Enforcement of applet boundaries in Java card systems
- Analyse de sécurité de logiciels système par typage statique. (Security analysis of system code using static typing)
- Information Flow Testing
- Information Flow Analysis Based Security Checking of Health Service Composition Plans
Related papers
- A Framework for Translating a High Level Security Policy into Low Level Security Mechanisms
- A framework for translating a high level security policy into low level security mechanisms
- A Survey of Computer Security Models
- Design and implementation of credible security platform of network
- Dealing with Multi Security Policies in Communication Networks
- How Secure is Secure: Some Thoughts on Security Metrics.
- Embedding Model-Based Security Policies in Software Development