We show how static analysis for secure information flow can be expressed and proved correct entirely within the framework of abstract interpretation. The key idea is to define a Galois connection that directly approximates the hyperproperty of interest. To enable use of such Galois connections, we introduce a fixpoint characterisation of hypercollecting semantics, i.e. a "set of sets" transformer. This makes it possible to systematically derive static analyses for hyperproperties entirely within the calculational framework of abstract interpretation. We evaluate this technique by deriving example static analyses. For qualitative information flow, we derive a dependence analysis similar to the logic of Amtoft and Banerjee (SAS'04) and the type system of Hunt and Sands (POPL'06). For quantitative information flow, we derive a novel cardinality analysis that bounds the leakage conveyed by a program instead of simply deciding whether it exists. This encompasses problems that are hypersafety but not k-safety. We put the framework to use and introduce variations that achieve precision rivalling the most recent and precise static analyses for information flow.
We show how static analysis for secure information flow can be expressed and proved correct entirely within the framework of abstract interpretation. The key idea is to define a Galois connection that directly approximates the hyperproperty of interest. To enable use of such Galois connections, we introduce a fixpoint characterisation of hypercollecting semantics, i.e. a "set of sets" transformer. This makes it possible to systematically derive static analyses for hyperproperties entirely within the calculational framework of abstract interpretation. We evaluate this technique by deriving example static analyses. For qualitative information flow, we derive a dependence analysis similar to the logic of Amtoft and Banerjee (SAS'04) and the type system of Hunt and Sands (POPL'06). For quantitative information flow, we derive a novel cardinality analysis that bounds the leakage conveyed by a program instead of simply deciding whether it exists. This encompasses problems that are hypersafety but not k-safety. We put the framework to use and introduce variations that achieve precision rivalling the most recent and precise static analyses for information flow.
Part 4: Software SecurityInternational audienceNovel approaches for dynamic information flow monitoring are promising since they enable permissive (accepting a large subset of executions) yet sound (rejecting all insecure executions) enforcement of non-interference. In this paper, we present a dynamic information flow monitor for a language supporting pointers. Our flow-sensitive monitor relies on prior static analysis in order to soundly enforce non-interference. We also propose a program transformation that preserves the behavior of initial programs and soundly inlines our security monitor. This program transformation enables both dynamic and static verification of non-interference
Fine grained information flow monitoring can in principle address a wide range of security and privacy goals, for example in web applications. But it is very difficult to achieve sound monitoring with acceptable runtime cost and sufficient precision to avoid impractical restrictions on programs and policies. We present a systematic technique for design of monitors that are correct by construction. It encompasses policies with downgrading. The technique is based on abstract interpretation which is a standard basis for static analysis of programs. This should enable integration of a wide range of analysis techniques, enabling more sophisticated engineering of monitors to address the challenges of precision and scaling to widely used programming languages.
RESUMO -Os autores descrevem o caso de uma mulher branca de 24 anos de idade admitida com lupus eritematoso sistêmico (com 4 anos de evolução de doença) e início recente de miastenia gravis. São discutidos os principais diagnósticos diferenciais para a fraqueza muscular e a fadiga apresentadas por esta paciente. Uma revisão de literatura abordando a associação de miastenia gravis e lupus eritematoso é feita, com ênfase às características clínicas desses pacientes e ao papel do timoma e timectomia no desenvolvimento de lupus eritematoso em pacientes previamente miastênicos.PALAVRAS-CHAVE: lupus eritematoso sistêmico, miastenia gravis. Systemic lupus erythematosus and myasthenia gravis: case reportABSTRACT -We report the case of a 24-year-old white woman admitted with a four year diagnosis of systemic lupus erythematosus and the recent onset of myasthenia gravis discussing the main differential diagnosis of weakness and fatigue in this patient. A review of literature approaching the association of myasthenia gravis and systemic lupus erythematosus is also done with emphasis on the clinical characteristics of these patients and the role of thymoma and thymectomy in the development of systemic lupus erythematosus in myasthenic patients.KEY WORDS: systemic lupus erythematosus, myasthenia gravis.O lupus eritematoso sistêmico (LES) e a miastenia gravis (MG) são doenças pouco frequentes, mas não raras. A prevalência de LES é de 1,5 a 5 casos para cada 10000 habitantes enquanto a MG ocorre pelo menos uma vez em cada 10000 indivíduos. Desta forma, a probabilidade de um paciente desenvolver uma associação dessas duas doenças é extremamente baixa, mesmo quando recordamos que pacientes acometidos por uma primeira doença autoimune apresentam maior propensão para o desenvolvimento de uma segunda afecção desse mesmo grupo. Embora a associação de LES e MG tenha sido descrita na literatura, sua ocorrência não foi claramente explicada por estudos epidemiológicos. RELATO DO CASOUma mulher branca de 24 anos de idade foi admitida no hospital com insuficiência respiratória aguda. Visão dupla, alteração da fala e dificuldade para deglutir estavam presentes nos dois meses que precederam a admissão. Quatro anos antes desta internação, foi feito diagnóstico de lupus eritematoso sistêmico através da detecção de lesões discóides cutâneas (Fig 1 ), fotossensibilidade, anticorpo antinuclear positivo com título de 1:640 e padrão homogêneo, proteinúria não seletiva de 0,72g/L/24h e uma preparação positiva para pesquisa de
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.
customersupport@researchsolutions.com
10624 S. Eastern Ave., Ste. A-614
Henderson, NV 89052, USA
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Copyright © 2024 scite LLC. All rights reserved.
Made with 💙 for researchers
Part of the Research Solutions Family.