An information-leak analysis system based on program slicing

Author:Yokomori, R; Ohata, F; Takata, Y; Seki, H; Inoue, K

Article Title:An information-leak analysis system based on program slicing

Abstract:
For programs using secret information such as credit card numbers, preventing information-leaks is important. Denning, for example, has proposed a mechanism to certify that a given program does not violate a security policy. Kuninobu, on the other hand, has proposed a more practical framework for calculating the secrecy level of each output value from the secrecy level set to each input value, but no implementation has been yet explored. In this paper, we propose an implementation method for information-leak analysis, and show a system we have implemented based on program slicing. We have applied this system to a credit card program. Our results show that information-leak analysis before practical use of the program is important. (C) 2002 Elsevier Science B.V. All rights reserved.

Keywords: program slice; information-leak analysis; program dependence graph; procedural language

DOI: 10.1016/S0950-5849(02)00127-1

Source:INFORMATION AND SOFTWARE TECHNOLOGY

Welcome to correct the error, please contact email: humanisticspider@gmail.com