Strong non-leak guarantees for workflow models

@inproceedings{Accorsi2011StrongNG,
  title={Strong non-leak guarantees for workflow models},
  author={Rafael Accorsi and Claus Wonnemann},
  booktitle={SAC},
  year={2011}
}
Despite the correct deployment of access control mechanisms, information leaks can persist and undermine the compliance of workflows to regulations and policies. This paper proposes InDico, a framework for the automated detection of information leaks in workflow models based on static information flow analysis. InDico identifies leaks induced by the structure of the workflow, i.e. its control flow. To this end, it translates workflow models, e.g. in BPEL or BPMN, into Petri nets and conducts… CONTINUE READING

Similar Papers

Citations

Publications citing this paper.
SHOWING 1-10 OF 31 CITATIONS

Certified Information Flow Analysis of Service Implementations

  • 2018 IEEE 11th Conference on Service-Oriented Computing and Applications (SOCA)
  • 2018

Non-Interference Enforcement in Bounded Petri Nets

  • 2018 IEEE Conference on Decision and Control (CDC)
  • 2018
VIEW 2 EXCERPTS
CITES BACKGROUND

Non-interference assessment in bounded Petri nets via Integer Linear Programming

  • 2018 Annual American Control Conference (ACC)
  • 2018
VIEW 2 EXCERPTS
CITES BACKGROUND

References

Publications referenced by this paper.

Intensional specifications of security protocols

  • Proceedings 9th IEEE Computer Security Foundations Workshop
  • 1996
VIEW 3 EXCERPTS
HIGHLY INFLUENTIAL