In the landmark paper on the theoretical siDe of Polymer,Ligatti and his co-authors have identified a new class of enforcement mechanisms based on the notion of edit automata, that can transform sequences and enforce more than simple safety properties.We show that there is a gap between the edit automata that one can possibly write (e.g. by Ligatti himself in his running example) and the edit automata that are actually constructed according the theorems from Ligatii's IJIS paper and IC follow-up papers by Talhi et al. "Ligatti's automata" are just a particular kind of edit automata.Thus, we re-open a question which seemed to have received a definitive answer: you have written your security enforcement mechanism (aka your edit automata); does it really enforce the security policy you wanted? ©Springer-Verlag Berlin Heidelberg 2009.
Do You Really Mean What You Actually Enforced? Edit Automata Revisited
Bielova, Nataliia;Massacci, Fabio
2009-01-01
Abstract
In the landmark paper on the theoretical siDe of Polymer,Ligatti and his co-authors have identified a new class of enforcement mechanisms based on the notion of edit automata, that can transform sequences and enforce more than simple safety properties.We show that there is a gap between the edit automata that one can possibly write (e.g. by Ligatti himself in his running example) and the edit automata that are actually constructed according the theorems from Ligatii's IJIS paper and IC follow-up papers by Talhi et al. "Ligatti's automata" are just a particular kind of edit automata.Thus, we re-open a question which seemed to have received a definitive answer: you have written your security enforcement mechanism (aka your edit automata); does it really enforce the security policy you wanted? ©Springer-Verlag Berlin Heidelberg 2009.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione



