DocumentCode :
2947840
Title :
Learning is Change in Knowledge: Knowledge-Based Security for Dynamic Policies
Author :
Askarov, Aslan ; Chong, Su Sin
fYear :
2012
fDate :
25-27 June 2012
Firstpage :
308
Lastpage :
322
Abstract :
In systems that handle confidential information, the security policy to enforce on information frequently changes: new users join the system, old users leave, and sensitivity of data changes over time. It is challenging, yet important, to specify what it means for such systems to be secure, and to gain assurance that a system is secure. We present a language-based model for specifying, reasoning about, and enforcing information security in systems that dynamically change the security policy. We specify security for such systems as a simple and intuitive extensional knowledge-based semantic condition: an attacker can only learn information in accordance with the current security policy. Importantly, the semantic condition is parameterized by the ability of the attacker. Learning is about change in knowledge, and an observation that allows one attacker to learn confidential information may provide a different attacker with no new information. A program that is secure against an attacker with perfect recall may not be secure against a more realistic, weaker, attacker. We introduce a compositional model of attackers that simplifies enforcement of security, and demonstrate that standard information-flow control mechanisms, such as security-type systems and information-flow monitors, can be easily adapted to enforce security for a broad and useful class of attackers.
Keywords :
knowledge based systems; learning (artificial intelligence); security of data; semantic networks; confidential information handling; dynamic policies; information security; information-flow control mechanisms; information-flow monitors; knowledge-based security; knowledge-based semantic condition; language-based model; security policy; security-type systems; Indexes; Information security; Knowledge based systems; Semantics; Standards; Syntactics; Information flow; dynamic policies; security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Foundations Symposium (CSF), 2012 IEEE 25th
Conference_Location :
Cambridge, MA
ISSN :
1940-1434
Print_ISBN :
978-1-4673-1918-8
Electronic_ISBN :
1940-1434
Type :
conf
DOI :
10.1109/CSF.2012.31
Filename :
6266168
Link To Document :
بازگشت