Abstract

Information flow control (IFC) is useful in preventing information leakage during software execution. Our survey reveals that no IFC model is applied on the entire software development process. Applying an IFC model on the entire software development process offers the following features: (1) viewpoints of all stakeholders (i.e., customers and analysts) can be included and (2) the IFC model helps correcting statements that may leak information during every development phase. In addition that no IFC model is applied to the entire software development process, we failed to identify an IFC model that can reduce runtime overhead. According to the above description, we designed a new IFC model named PrcIFC (process IFC). PrcIFC is applied on the entire software development process. Moreover, PrcIFC is disabled after software testing to reduce runtime overhead.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call