Vaughan, Jeffrey A.Chong, Stephen2012-02-222011Vaughan, Jeffrey A. and Stephen Chong. 2011. Inference of expressive declassification policies. In Proceedings of the 2011 IEEE Symposium on Security and Privacy (SP): May 22-25, 2011, Berkeley, CA.978-0-7695-4402-1978-1-4577-0147-41081-6011http://nrs.harvard.edu/urn-3:HUL.InstRepos:8207505We explore the inference of expressive human-readable declassification policies as a step towards providing practical tools and techniques for strong language-based information security. Security-type systems can enforce expressive information-security policies, but can require enormous programmer effort before any security benefit is realized. To reduce the burden on the programmer, we focus on inference of expressive yet intuitive information-security policies from programs with few programmer annotations. We define a novel security policy language that can express what information a program may release, under what conditions (or, when) such release may occur, and which procedures are involved with the release (or, where in the code the release occur). We describe a dataflow analysis for precisely inferring these policies, and build a tool that instantiates this analysis for the Java programming language. We validate the policies, analysis, and our implementation by applying the tool to a collection of simple Java programs.en-USinformation securityjavaobserverssemanticssyntacticsdata flow analysisinference mechanismssecurity of datadeclassification policiesinference of security policiesinformation flowlanguage-based securitysecurity-type systemssecurity policy languagelanguage-based information securityexpressive human-readable declassification policiesInference of Expressive Declassification PoliciesConference Paper2012-02-2210.1109/SP.2011.20