{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:41:45Z","timestamp":1750308105020,"version":"3.41.0"},"reference-count":28,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2005,5,15]],"date-time":"2005-05-15T00:00:00Z","timestamp":1116115200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGSOFT Softw. Eng. Notes"],"published-print":{"date-parts":[[2005,7]]},"abstract":"<jats:p>This paper presents a new approach to using dynamic information flow analysis to detect attacks against application software. The approach can be used to reveal and, under some conditions, to prevent attacks that violate a specified information flow policy or exhibit a known information flow signature. When used in conjunction with automatic cluster analysis, the approach can also reveal novel attacks that exhibit unusual patterns of information flows. A set of prototype tools implementing the approach have been developed for Java byte code programs. Case studies in which this approach was applied to several subject programs are described.<\/jats:p>","DOI":"10.1145\/1082983.1083216","type":"journal-article","created":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T19:28:32Z","timestamp":1131391712000},"page":"1-7","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Using dynamic information flow analysis to detect attacks against applications"],"prefix":"10.1145","volume":"30","author":[{"given":"Wes","family":"Masri","sequence":"first","affiliation":[{"name":"American University of Beirut, Beirut, Lebanon"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andy","family":"Podgurski","sequence":"additional","affiliation":[{"name":"Case Western Reserve University, Cleveland, OH"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,5,15]]},"reference":[{"volume-title":"A Minimal Trusted Computing Base for Dynamically Ensuring Secure Information Flow. Project Aries TM-015 (November","year":"2001","author":"Brown J.","key":"e_1_2_1_1_1"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/359636.359712"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1987.232894"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/381473.381509"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/503209.503243"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5555\/829515.830554"},{"key":"e_1_2_1_9_1","first-page":"2","volume":"17","author":"Fenton","year":"1974","journal-title":"Memoryless Subsystems. The Computer Journal"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/24039.24041"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/1947337.1947356"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/647593.728880"},{"volume-title":"IBM","year":"2001","author":"Console","key":"e_1_2_1_13_1"},{"volume-title":"The Enforcement of Security Policies for Computation. Journal of Computer and Systems Sciences","year":"1978","author":"Jones A.","key":"e_1_2_1_14_1"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/362375.362389"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1062455.1062531"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/337180.337195"},{"volume-title":"12th National Computer Security Conference","year":"1989","author":"Liepins G.","key":"e_1_2_1_18_1"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2004.17"},{"key":"e_1_2_1_21_1","unstructured":"Open Source Vulnerability Database (OSVDB): www.osvdb.org.  Open Source Vulnerability Database (OSVDB): www.osvdb.org."},{"key":"e_1_2_1_22_1","unstructured":"The PERL Directory www.perl.org.  The PERL Directory www.perl.org."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.58784"},{"volume-title":"20th NIST\/NCSC National Information Systems Security Conference","year":"1997","author":"Porras P. A.","key":"e_1_2_1_25_1"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/367008.367022"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.5555\/1754701.1754707"},{"key":"e_1_2_1_29_1","unstructured":"The Byte Code Engineering Library (BCEL) The Apache Jakarta Project http:\/\/jakarta.apache.org\/bcel. Apache Software Foundation 2003.  The Byte Code Engineering Library (BCEL) The Apache Jakarta Project http:\/\/jakarta.apache.org\/bcel. Apache Software Foundation 2003."},{"key":"e_1_2_1_30_1","unstructured":"Tomcat Java Application Server: http:\/\/jakarta.apache.org\/tomcat.  Tomcat Java Application Server: http:\/\/jakarta.apache.org\/tomcat."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"}],"container-title":["ACM SIGSOFT Software Engineering Notes"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1082983.1083216","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1082983.1083216","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:08:06Z","timestamp":1750262886000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1082983.1083216"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,5,15]]},"references-count":28,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2005,7]]}},"alternative-id":["10.1145\/1082983.1083216"],"URL":"https:\/\/doi.org\/10.1145\/1082983.1083216","relation":{"is-identical-to":[{"id-type":"doi","id":"10.1145\/1083200.1083216","asserted-by":"subject"}]},"ISSN":["0163-5948"],"issn-type":[{"type":"print","value":"0163-5948"}],"subject":[],"published":{"date-parts":[[2005,5,15]]},"assertion":[{"value":"2005-05-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}