Abstract:
We show how a variety of confidentiality properties can be expressed in terms of the abstraction mechanisms that CSP provides. We argue that determinism of the abstracted low-security viewpoint provides the best type of property. By changing the form of abstraction mechanism we are able to model di#erent assumptions about how systems behave, including handling the distinction between input and output actions. A detailed analysis of the nature of nondeterminism shows why certain security properties have had the paradoxical property of not being preserved by refinement-- a disadvantage not shared by the determinism-based conditions. Finally we give an e#cient algorithm for testing the determinism properties on a model-checker.
Citations
|
433
|
Security policies and security models
– Goguen, Meseguer
- 1982
|
|
68
|
Noninterference and the composability of security properties
– McCullough
- 1988
|
|
62
|
An improved failures model for communicating processes
– Brookes, Roscoe
- 1985
|
|
55
|
Noninterference through determinism
– Roscoe, Woodcock, et al.
- 1996
|
|
22
|
Model-checking CSP. In A Classical Mind: Essays in Honour of C A
– Roscoe
- 1994
|
|
9
|
A comparison of non-interference and non-deducibility using CSP
– Allen
- 1991
|
|
7
|
Specifying Security Properties
– Jacob
- 1990
|
|
6
|
Verifying a replicated database: A case study in model-checking CSP
– Roscoe, MacCarthy
- 1994
|
|
4
|
The Formal Development of Secure Systems
– Graham-Cumming
- 1992
|
|
4
|
Unbounded Nondeterminism
– Roscoe
- 1993
|
|
3
|
A model for communicating sequential processes, Oxford University D.Phil. thesis
– Brookes
- 1983
|
|
2
|
An alternative order for the failures model , in `Two papers on CSP', technical monograph PRG-67
– Roscoe
- 1988
|
|
2
|
Composing and decomposing processes under security properties
– Roscoe, Wulf
- 1995
|
|
2
|
A CSP formulation of noninterference, Cipher, pp
– Ryan
|
|
1
|
Security properties consistent with the testing semantics for communicating processes
– Johnson, Thayer
- 1989
|
|
1
|
Analysing TM FS : a Study of Nondeterminism
– Reed, Roscoe
|