On Improvements of Low-Deterministic Security (2016)
<p>Abstract: "Low-security observable determinism (LSOD), as introduced by Roscoe and Zdancewic [18,24], is the simplest criterion which guarantees probabilistic noninterference for concurrent programs. But LSOD prohibits any, even secure low-nondeterminism. Giffhorn developed an improvement, named RLSOD, which allows some secure low-nondeterminism, and can handle full Java with high precision [5]. In this paper, we describe a new generalization of RLSOD. By applying aggressive program analysis, in particular dominators for multi-threaded programs, precision can be boosted and false alarms minimized. We explain details of the new algorithm, and provide a soundness proof. The improved RLSOD is integrated into the JOANA tool; a case study is described. We thus demonstrate that low-deterministic security is a highly precise and practically mature software security analysis method."</p>
Read the full article at pp.ipd.kit.edu →
Related stories
- Hacker News · 1 points · 3 days ago
- Forging 1024-bit RSA signatures in nearly SNFS timeeprint.iacr.orgLobsters · 7 points · 7 days ago
- Ars Technica · 0 points · 9 days ago
- Hacker News · 1 points · 4 days ago
- Hacker News · 1 points · 7 days ago
- Torvalds On Linux Security Modulesphoronix.comLobsters · 23 points · 10 months ago