Re: Capability modelling tools
Thomas Leonard <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAG4opy-T9pn28dGjqvVaN1Ri5sE-B-U37QYXWw63zu1vwHbZEg@mail.gmail.com> |
On 27 April 2011 00:55, Toby Murray <[email protected]> wrote: > On 26 April 2011 19:17, Thomas Leonard <[email protected]> wrote: >> Hi all, >> >> I'm doing a bit of modelling work at the moment, looking to see how >> capabilities may propagate through a system, and the effects of >> various components being compromised, etc. I found the Scollar and >> Authodox tools for this, but they didn't quite fit what I wanted to >> do. [...] >> In the end, I wrote a little modeller of my own. It's similar to >> Scollar in many ways, but it also models "invocations" (not just >> objects). An invocation is a particular call to a method, representing >> the stack-frame that is created and the local variables of this stack >> frame. You can then (separately) specify how the real invocations are >> to be aggregated. > > Have you thought about formalising the approach your modeller > implements, and proving whether aggregations are sound with respect to > this (hypothetical) formal model? After reading up a bit more about this, I realised I was basically just doing a standard points-to analysis (although with a slightly unusual choice of context). However, I did write an article about it, which has now been published: Thomas Leonard, Martin Hall-May, and Mike Surridge. 2013. Modelling Access Propagation in Dynamic Systems. ACM Trans. Inf. Syst. Secur. 16, 2, Article 5 (September 2013), 31 pages. DOI=10.1145/2516951.2516952 http://doi.acm.org/10.1145/2516951.2516952 It should be possible to download it from this link: http://roscidus.com/blog/about/#the-serscis-access-modeller However, I'm not working on SAM at the moment as I no longer work at the university. -- Dr Thomas Leonard http://0install.net/ GPG: 9242 9807 C985 3C07 44A6 8B9A AE07 8280 59A5 3CC1 GPG: DA98 25AE CAD0 8975 7CDA BD8E 0713 3F96 CA74 D8BA