CRMay 8, 2015

The Anatomy and Facets of Dynamic Policies

arXiv:1505.02021v323 citations
Originality Synthesis-oriented
AI Analysis

This work addresses the problem of fragmented approaches to dynamic security policies for researchers and practitioners in computer security, but it is incremental as it synthesizes and organizes existing insights rather than proposing new methods.

The paper tackles the challenge of specifying and giving meaning to dynamic information flow policies by synthesizing existing knowledge to establish common terminology, best practices, and reasoning frameworks, introducing facets to illuminate policy semantics and examining policy anatomy and specification expressiveness.

Information flow policies are often dynamic; the security concerns of a program will typically change during execution to reflect security-relevant events. A key challenge is how to best specify, and give proper meaning to, such dynamic policies. A large number of approaches exist that tackle that challenge, each yielding some important, but unconnected, insight. In this work we synthesise existing knowledge on dynamic policies, with an aim to establish a common terminology, best practices, and frameworks for reasoning about them. We introduce the concept of facets to illuminate subtleties in the semantics of policies, and closely examine the anatomy of policies and the expressiveness of policy specification mechanisms. We further explore the relation between dynamic policies and the concept of declassification.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes