|
TR-681-03
Edit Automata: Enforcement Mechanisms for Run-time Security Policies |
|
| Authors: | Ligatti, Jay, Bauer, Lujo, Walker, David |
| Date: | May 2003 |
| Pages: | 43 |
| Download Formats: | [Postscript] [PDF] |
We analyze the space of security policies that can be enforced by monitoring and modifying programs at run time. Our program monitors, called edit automata, are abstract machines that examine the sequence of application program actions and transform the sequence when it deviates from a specified policy. Edit automata have a rich set of transformational powers: They may terminate the application, thereby truncating the program action stream; they may suppress undesired or dangerous actions without necessarily terminating the program; and they may also insert additional actions into the event stream. |
|