Title
Beyond Stack Inspection: A Unified Access-Control and Information-Flow Security Model
Abstract
Modern component-based systems, such as Java and Microsoft .NET Common Language Runtime (CLR), have adopted Stack-Based Access Control (SBAC). Its purpose is to use stack inspection to verify that all the code responsible for a security-sensitive action is sufficiently authorized to perform that action. Previous literature has shown that the security model enforced by SBAC is flawed in that stack inspection may allow unauthorized code no longer on the stack to influence the execution of security-sensitive code. A different approach, History-Based Access Control (HBAC), is safe but may prevent authorized code from executing a security-sensitive operation if less trusted code was previously executed. In this paper, we formally introduce Information-Based Access Control (IBAC), a novel security model that verifies that all and only the code responsible for a security-sensitive operation is sufficiently authorized. Given an access-control policy á, we present a mechanism to extract from it an implicit integrity policy é, and we prove that IBAC enforces é. Furthermore, we discuss large-scale application code scenarios to which IBAC can be successfully applied.
Year
DOI
Venue
2007
10.1109/SP.2007.10
IEEE Symposium on Security and Privacy
Keywords
Field
DocType
authorisation,data flow analysis,data integrity,object-oriented programming,program verification,Java,Microsoft .NET common language runtime,authorization,code verification,component-based system,data integrity,history-based access control,information-flow security model,stack inspection,unified access-control
Permission,Computer science,Computer security,Data-flow analysis,Information security,Data integrity,Access control,Common Language Runtime,Computer security model,Code Access Security,Operating system
Conference
ISSN
ISBN
Citations 
1081-6011
0-7695-2848-1
28
PageRank 
References 
Authors
1.08
35
3
Name
Order
Citations
PageRank
Marco Pistoia189658.12
Anindya Banerjee2132470.68
David Naumann3110184.12