Co-Inflow: Coarse-grained Information Flow Control for Java-like Languages
Jian Xiang, Stephen Chong
摘要
Coarse-grained dynamic information-flow control (IFC) is a good match for imperative object-oriented programming languages such as Java. Java language abstractions align well with coarse-grained IFC concepts, and so Java can be cleanly extended with coarse-grained dynamic IFC without requiring significantly different design patterns or excessive security annotations, and without excessive performance overhead. We present Co-Inflow: an extension of Java with coarse-grained dynamic IFC. By careful design choices and defaults, a programmer typically needs to add very few annotations to a Java program to convert it to a Co-Inflow program with relatively good precision. Additional annotations can improve precision. We achieve this tradeoff between precision and annotation burden by instantiating and specializing recent advances in coarsegrained IFC for a Java-like setting, and by using opaque labeled values: a restriction of labeled values that the Co-Inflow runtime automatically and securely creates and uses. We have captured the essence of Co-Inflow in a middle-weight imperative calculus, and proven that it provides a terminationinsensitive non-interference security guarantee. We have a prototype implementation of Co-Inflow and use it to evaluate the precision, usability, and potential performance of Co-Inflow.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Cocoon: Static Information Flow Control in RustAda Lamba, Max Taylor, Vincent Beardsley, Jacob Bambeck 等OOPSLA 2024 · 被引用 9 次
- Quest Complete: The Holy Grail of Gradual SecurityTianyu Chen, Jeremy G. SiekPLDI 2024 · 被引用 6 次
- General Data Protection Runtime: Enforcing Transparent GDPR Compliance for Existing ApplicationsDavid Klein, Benny Rolle, Thomas Barber, Manuel Karl 等CCS 2023 · 被引用 5 次
- Carapace: Static-Dynamic Information Flow Control in RustVincent Beardsley, Chris Xiong, Ada Lamba, Michael D. BondOOPSLA 2025 · 被引用 3 次
- SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability DetectionKeyu Man, Zhongjie Wang, Yu Hao, Shenghan Zheng 等S&P 2025
它引用的顶会 Paper2
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato 等USENIX Security 2016 · 被引用 296 次
- Practical DIFC Enforcement on AndroidAdwait Nadkarni, Benjamin Andow, William Enck, Somesh JhaUSENIX Security 2016 · 被引用 57 次
相关 Paper
- A Type System for Optimizing Dynamic IFCDaniel Galán Pascual, François Hublet, Srđan Krstić, Roman Fischer 等OOPSLA 2026
- Giving semantics to program-counter labels via secure effectsAndrew K. Hirsch, Ethan CecchettiPOPL 2021 · 被引用 2 次
- Reconciling noninterference and gradual typingArthur Azevedo de Amorim, Matt Fredrikson, Limin JiaLICS 2020 · 被引用 12 次
- Towards Generating Thread-Safe Classes AutomaticallyHaichi Wang, Zan Wang, Jun Sun, Shuang Liu 等ASE 2020 · 被引用 1 次
- AtomiS: Data-Centric Synchronization Made PracticalHervé Paulino, Ana Almeida Matos, Jan Cederquist, Marco Giunti 等OOPSLA 2023
