Constellation, le dépôt institutionnel de l'Université du Québec à Chicoutimi

A modular pipeline for enforcement of security properties at runtime

Taleb Rania, Hallé Sylvain et Khoury Raphaël. (2023). A modular pipeline for enforcement of security properties at runtime. Annals of Telecommunications, 78, p. 429-457.

[thumbnail of Taleb_et_al_2023_AnnTelecom.pdf]
Prévisualisation
PDF - Version acceptée
860kB

URL officielle: https://dx.doi.org/doi:10.1007/s12243-023-00952-z

Résumé

Runtime enforcement ensures the respect of a user-specified security policy by a program by providing a valid replacement for any misbehaving sequence of events that may occur during that program’s execution. However, depending on the capabilities of the enforcement mechanism, multiple possible replacement sequences may be available, and the current literature is silent on the question of how to choose the optimal one. Furthermore, the current design of runtime monitors imposes a substantial burden on the designer, since the entirety of the monitoring task is accomplished by a monolithic construct, usually an automata-based model. In this paper, we propose a new modular model of enforcement monitors, in which the tasks of altering the execution, ensuring compliance with the security policy, and selecting the optimal replacement are split into three separate modules, which simplifies the creation of runtime monitors. We implement this approach by using the event stream processor BeepBeep and a use case is presented. Experimental evaluation shows that our proposed framework can dynamically select an adequate enforcement actions at runtime, without the need to manually define an enforcement monitor.

Type de document:Article publié dans une revue avec comité d'évaluation
ISSN:0003-4347
Volume:78
Pages:p. 429-457
Version évaluée par les pairs:Oui
Date:2023
Identifiant unique:10.1007/s12243-023-00952-z
Sujets:Sciences naturelles et génie > Sciences mathématiques > Informatique
Département, module, service et unité de recherche:Départements et modules > Département d'informatique et de mathématique
Mots-clés:modular model, optimal replacement
Déposé le:06 sept. 2023 14:09
Dernière modification:17 avr. 2024 04:00
Afficher les statistiques de telechargements

Éditer le document (administrateurs uniquement)

Creative Commons LicenseSauf indication contraire, les documents archivés dans Constellation sont rendus disponibles selon les termes de la licence Creative Commons "Paternité, pas d'utilisation commerciale, pas de modification" 2.5 Canada.

Bibliothèque Paul-Émile-Boulet, UQAC
555, boulevard de l'Université
Chicoutimi (Québec)  CANADA G7H 2B1
418 545-5011, poste 5630