作者: Peter Drábik , Fabio Martinelli , Charles Morisset
DOI: 10.1007/978-3-642-33383-5_19
关键词:
摘要: A run-time enforcement mechanism is a program in charge of ensuring that all the traces system satisfy given security policy. Following Schneider's seminal work, there have been several approaches defining what kind policies can be automatically enforced, and particular, non-safety properties cannot correctly transparently enforced. In this paper, we first propose to build an using abstract notion selector. We then quantify inexact property by mechanism, considering both leading non-secure output secure not output, thus formalizing intuitive security/usability tradeoff. Finally, refine when probabilistic quantitative information known about traces. illustrate different concepts with running example, representing policy dealing emergency situations.