article Open access

Static Analysis of Information Release in Interactive Programs

Research footprint

At a glance

Citations
0
References
14
Comments
0
Paper overview

Öz

In this paper we present a model for analysing information release (or leakage) in programs written in a simple imperative language. We present the se- mantics of the language, an attacker model, and the notion of an information release policy. Our key contribution is the static analysis technique to compute information release of programs and to verify it against a policy. We demonstrate our approach by analysing information released to an attacker by faulty password checking pro- grams; our example is inspired by a known flaw in versions of OpenSSH distributed with various Unix, Linux, and OpenBSD operating systems.

Record transparency

Publication details

DOI
10.14279/tuj.eceasst.35.544
OpenAlex
W1484849366
Document type
article
Language
EN
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.