Hybrid information-flow monitors use a combination of static analysis and dynamic mechanisms to provide precise strong information security guarantees. However, unlike purely static mechanisms for information security, hybrid information-flow monitors incur run-time overhead. We show how static analyses can be used to make hybrid information- flow monitors more efficient, in two ways. First, a simple static analysis can determine when it is sound for a monitor to stop tracking the security level of certain variables. This potentially reduces run-time overhead of the monitor, particularly in applications where sensitive (i.e., confidential or untrusted) data is infrequently introduced to the system. Second, we derive sufficient conditions fo...
Controlling confidential information in concurrent systems is difficult, due to covert channels resu...
Abstract—Controlling confidential information in concurrent systems is difficult, due to covert chan...
We present a simple architectural mechanism called dynamicinformation flow tracking that can signifi...
We present a novel progress-sensitive, flow-sensitive hybrid information-flow control monitor for an...
This paper seeks to answer fundamental questionsabout trade-offs between static and dynamic security...
International audienceMotivated by the problem of stateless web tracking (fingerprinting), we propos...
Information flow analysis is an effective way to check useful security properties, such as whether s...
Part 9: Software SecurityInternational audienceWe present a novel progress-sensitive, flow-sensitive...
Historically, dynamic techniques are the pioneers of the area of informationflow in the 70’s. In the...
Controlling confidential information in concurrent systems is difficult, due to covert channels resu...
We present an information flow monitoring mechanism for sequential programs. The monitor executes a ...
There are different paradigms for enforcing information flow and declassification policies. These ap...
We present a simple architectural mechanism called dynamic information flow tracking that can signif...
Over the years, computer systems and applications have grown significantly complex while handling a ...
In the context of systems security, information flows play a central role. Unhandled information flo...
Controlling confidential information in concurrent systems is difficult, due to covert channels resu...
Abstract—Controlling confidential information in concurrent systems is difficult, due to covert chan...
We present a simple architectural mechanism called dynamicinformation flow tracking that can signifi...
We present a novel progress-sensitive, flow-sensitive hybrid information-flow control monitor for an...
This paper seeks to answer fundamental questionsabout trade-offs between static and dynamic security...
International audienceMotivated by the problem of stateless web tracking (fingerprinting), we propos...
Information flow analysis is an effective way to check useful security properties, such as whether s...
Part 9: Software SecurityInternational audienceWe present a novel progress-sensitive, flow-sensitive...
Historically, dynamic techniques are the pioneers of the area of informationflow in the 70’s. In the...
Controlling confidential information in concurrent systems is difficult, due to covert channels resu...
We present an information flow monitoring mechanism for sequential programs. The monitor executes a ...
There are different paradigms for enforcing information flow and declassification policies. These ap...
We present a simple architectural mechanism called dynamic information flow tracking that can signif...
Over the years, computer systems and applications have grown significantly complex while handling a ...
In the context of systems security, information flows play a central role. Unhandled information flo...
Controlling confidential information in concurrent systems is difficult, due to covert channels resu...
Abstract—Controlling confidential information in concurrent systems is difficult, due to covert chan...
We present a simple architectural mechanism called dynamicinformation flow tracking that can signifi...