Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security 2017
DOI: 10.1145/3133956.3134080
|View full text |Cite
|
Sign up to set email alerts
|

Verifying Security Policies in Multi-agent Workflows with Loops

Abstract: We consider the automatic verification of information flow security policies of web-based workflows, such as conference submission systems like EasyChair. Our workflow description language allows for loops, non-deterministic choice, and an unbounded number of participating agents. e information flow policies are specified in a temporal logic for hyperproperties. We show that the verification problem can be reduced to the satisfiability of a formula of first-order linear-time temporal logic, and provide decidab… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
22
0

Year Published

2019
2019
2021
2021

Publication Types

Select...
5
1

Relationship

2
4

Authors

Journals

citations
Cited by 35 publications
(22 citation statements)
references
References 33 publications
(57 reference statements)
0
22
0
Order By: Relevance
“…It would be interesting to see if the differences we observed for HyperLTL carry over to other hyperlogics (cf. [1,11,13,24]). One could extend the results of this paper to the reactive setting, where the program interacts with the environment.…”
Section: Discussionmentioning
confidence: 99%
See 2 more Smart Citations
“…It would be interesting to see if the differences we observed for HyperLTL carry over to other hyperlogics (cf. [1,11,13,24]). One could extend the results of this paper to the reactive setting, where the program interacts with the environment.…”
Section: Discussionmentioning
confidence: 99%
“…There has been a lot of recent progress in automatically verifying [14,[23][24][25] and monitoring [2,8,9,21,22,29,39] HyperLTL specifications. HyperLTL is also supported by a growing set of tools, including the model checker MCHyper [14,25], the satisfiability checkers EAHyper [20] and MGHyper [18], and the runtime monitoring tool RVHyper [21].…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…There has been much recent progress in automatically verifying [27,26,25,15,31] and monitoring [3,24,11,9,23,35,30] HyperLTL specifications. HyperLTL is also supported by a growing set of tools, including the model checkers HyperQube [31],…”
Section: Related Workmentioning
confidence: 99%
“…This problem also has been encountered in [10,11,19] where noninterference [13] is investigated for multi-agent workflows in the spirit of the conference management system from Fig. 1.…”
Section: Introductionmentioning
confidence: 98%