• DocumentCode
    1806579
  • Title

    Specification and Runtime Enforcement of Security Policies

  • Author

    Jin, Ying ; Zhang, Jing ; Zheng, Xiaojuan

  • Author_Institution
    Jilin Univ., Changchun
  • fYear
    2007
  • fDate
    18-21 Sept. 2007
  • Firstpage
    244
  • Lastpage
    249
  • Abstract
    The rapid growth in mobile and wireless communications entails serious problem of security. Formal methods can be used to help building secure mobile computing environment. Tabular expressions have proved to be useful and practical in formulating precise and complete documentation for computer systems. In this paper a framework for specification and runtime enforcement of security policies is proposed basing on the use of tabular expressions. A security policy can be specified with a tabular expression, and checking whether an application adheres to a given policy can be achieved by evaluating the tabular expression with respect to information intercepted at runtime. The advantages of our approach includes: (1) providing precise and readable specification of security policies; (2) developing a general policy enforcement engine rather than one policy enforcement engine for each security policy; (3)achieving low overheads by simplifying tabular expressions with static information of mobile code.
  • Keywords
    formal specification; mobile computing; security of data; system documentation; computer system documentation; formal methods; mobile communications; mobile computing environment; runtime enforcement; security policies specification; tabular expressions; wireless communication; Communication system security; Computer security; Concrete; Educational institutions; Engines; Information security; Mobile computing; Parallel processing; Runtime; Wireless communication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Parallel Computing Workshops, 2007. NPC Workshops. IFIP International Conference on
  • Conference_Location
    Liaoning
  • Print_ISBN
    978-0-7695-2943-1
  • Type

    conf

  • DOI
    10.1109/NPC.2007.105
  • Filename
    4351492