• DocumentCode
    2976265
  • Title

    On the (f)utility of untrusted data sanitization

  • Author

    Gehani, Ashish ; Hanz, David ; Rushby, John ; Denker, Grit ; DeLong, Rance

  • Author_Institution
    SRI Int., Menlo Park, CA, USA
  • fYear
    2011
  • fDate
    7-10 Nov. 2011
  • Firstpage
    1261
  • Lastpage
    1266
  • Abstract
    Data sanitization has been studied in the context of architectures for high assurance systems, language-based information flow controls, and privacy-preserving data publication. A range of sanitization strategies has been developed to address the wide variety of data content and contexts that arise in practice. It is therefore tempting to separate the complex downgrading operations into untrusted data sanitizers while leaving the verification of security policy to simpler trusted guards that mediate information flow between different sensitivity levels. We argue that this can be a false economy and may result in more restrictive information flow than is necessary. We also observe that the guarantees provided by language-based declassification algorithms do not hold without exacting requirements for the runtime environment, and that the satisfaction of these requirements is the precise goal of MILS architectures, making the two disciplines well-matched complements.
  • Keywords
    parallel languages; security of data; complex downgrading operations; data content; high assurance systems; language based declassification algorithms; language based information flow controls; privacy preserving data publication; untrusted data sanitization; Complexity theory; Context; Data models; Global Positioning System; Kernel; Runtime; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011
  • Conference_Location
    Baltimore, MD
  • ISSN
    2155-7578
  • Print_ISBN
    978-1-4673-0079-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2011.6127475
  • Filename
    6127475