CORC  > 软件研究所  > 互联网软件技术实验室  > 会议论文
a practical covert channel identification approach in source code based on directed information flow graph
Wu JingZheng ; Ding Liping ; Wang Yongji ; Han Wei
2011
会议名称2011 5th International Conference on Secure Software Integration and Reliability Improvement, SSIRI 2011
会议日期27-Jun-02
会议地点Jeju Island, Korea, Republic of
关键词Algorithms Building codes Computer operating systems Computer programming languages Graphic methods Software reliability
页码98-107
英文摘要Covert channel analysis is an important requirement when building secure information systems and identification is the most difficult task. Although some approaches were presented they are either experimental or constrained to some particular systems. This paper presents a practical approach based on directed information flow graph taking advantage of the source code analysis. The approach divides the whole system into serval independent modules and analyzes them respectively. All the shared variables and their caller functions are found out from the source codes and modeled into directed information flow graphs. When the information flow branches are visible and modifiable to the external interface a potential covert channel exists. Contributions made in this paper are as follows a modularized analysis scheme is proved and reduces the workloads of identifying a directed information flow graph algorithm is presented and used to model the covert channels more than 30 covert channels have been identified in Linux kernel source code using this scheme and a typical channel scenario is constructed. © 2011 IEEE.
收录类别EI
会议主办者Korea Software Engineering Society
会议录Proceedings - 2011 5th International Conference on Secure Software Integration and Reliability Improvement, SSIRI 2011
会议录出版地United States
ISBN号9780769544533
内容类型会议论文
源URL[http://124.16.136.157/handle/311060/14377]  
专题软件研究所_互联网软件技术实验室 _会议论文
推荐引用方式
GB/T 7714
Wu JingZheng,Ding Liping,Wang Yongji,et al. a practical covert channel identification approach in source code based on directed information flow graph[C]. 见:2011 5th International Conference on Secure Software Integration and Reliability Improvement, SSIRI 2011. Jeju Island, Korea, Republic of. 27-Jun-02.
个性服务
查看访问统计
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。


©版权所有 ©2017 CSpace - Powered by CSpace