History-sensitive versus future-sensitive approaches to security in distributed systems

Alejandro Mario Hernandez
(Technical University of Denmark)
Flemming Nielson
(Technical University of Denmark)

We consider the use of aspect-oriented techniques as a flexible way to deal with security policies in distributed systems. Recent work suggests to use aspects for analysing the future behaviour of programs and to make access control decisions based on this; this gives the flavour of dealing with information flow rather than mere access control. We show in this paper that it is beneficial to augment this approach with history-based components as is the traditional approach in reference monitor-based approaches to mandatory access control. Our developments are performed in an aspect-oriented coordination language aiming to describe the Bell-LaPadula policy as elegantly as possible. Furthermore, the resulting language has the capability of combining both history- and future-sensitive policies, providing even more flexibility and power.

In Simon Bliudze, Roberto Bruni, Davide Grohmann and Alexandra Silva: Proceedings Third Interaction and Concurrency Experience Guaranteed Interaction (ICE 2010), Amsterdam, The Netherlands, 10th of June 2010, Electronic Proceedings in Theoretical Computer Science 38, pp. 29–43.
Published: 26th October 2010.

ArXived at: https://dx.doi.org/10.4204/EPTCS.38.5 bibtex PDF

Comments and questions to: eptcs@eptcs.org
For website issues: webmaster@eptcs.org