DocumentCode
2976265
Title
On the (f)utility of untrusted data sanitization
Author
Gehani, Ashish ; Hanz, David ; Rushby, John ; Denker, Grit ; DeLong, Rance
Author_Institution
SRI Int., Menlo Park, CA, USA
fYear
2011
fDate
7-10 Nov. 2011
Firstpage
1261
Lastpage
1266
Abstract
Data sanitization has been studied in the context of architectures for high assurance systems, language-based information flow controls, and privacy-preserving data publication. A range of sanitization strategies has been developed to address the wide variety of data content and contexts that arise in practice. It is therefore tempting to separate the complex downgrading operations into untrusted data sanitizers while leaving the verification of security policy to simpler trusted guards that mediate information flow between different sensitivity levels. We argue that this can be a false economy and may result in more restrictive information flow than is necessary. We also observe that the guarantees provided by language-based declassification algorithms do not hold without exacting requirements for the runtime environment, and that the satisfaction of these requirements is the precise goal of MILS architectures, making the two disciplines well-matched complements.
Keywords
parallel languages; security of data; complex downgrading operations; data content; high assurance systems; language based declassification algorithms; language based information flow controls; privacy preserving data publication; untrusted data sanitization; Complexity theory; Context; Data models; Global Positioning System; Kernel; Runtime; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011
Conference_Location
Baltimore, MD
ISSN
2155-7578
Print_ISBN
978-1-4673-0079-7
Type
conf
DOI
10.1109/MILCOM.2011.6127475
Filename
6127475
Link To Document