• DocumentCode
    1534008
  • Title

    On the identification of covert storage channels in secure systems

  • Author

    Tsai, Chii-Ren ; Gligor, Virgil D. ; Chandersekaran, C. Sekar

  • Author_Institution
    VDG Inc., Chevy Chase, MD, USA
  • Volume
    16
  • Issue
    6
  • fYear
    1990
  • fDate
    6/1/1990 12:00:00 AM
  • Firstpage
    569
  • Lastpage
    580
  • Abstract
    A practical method for the identification of covert storage channels is presented and its application to the source code of the Secure Xenix kernel is illustrated. The method is based on the identification of all visible/alterable kernel variables by using information-flow analysis of language code. The method also requires that, after the sharing relationships among the kernel primitives and the visible/alterable variables are determined, the nondiscretionary access rules implemented by each primitive be applied to identify the potential storage channels. The method can be generalized to other implementation languages, and has the following advantages: it helps discover all potential storage channels is kernel code, thereby helping determine whether the nondiscretionary access rules are implemented correctly; it helps avoid discovery of false flow violations and their unnecessary analysis; and it helps identify the kernel locations where audit code and time-delay variables need to be placed for covert-channel handling
  • Keywords
    operating systems (computers); security of data; software engineering; Secure Xenix kernel; audit code; covert storage channels; covert-channel handling; false flow violations; identification; implementation languages; information-flow analysis; kernel locations; language code; nondiscretionary access rules; secure systems; sharing relationships; source code; time-delay variables; visible/alterable kernel variables; Communication channels; Communication system security; Control systems; Information analysis; Information security; Kernel; Operating systems; Secure storage; Timing; Voice mail;
  • fLanguage
    English
  • Journal_Title
    Software Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0098-5589
  • Type

    jour

  • DOI
    10.1109/32.55086
  • Filename
    55086