{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:23:59Z","timestamp":1750307039015,"version":"3.41.0"},"reference-count":35,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2012,7,1]],"date-time":"2012-07-01T00:00:00Z","timestamp":1341100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2012,7]]},"abstract":"<jats:p>Runtime monitoring is an increasingly popular method to ensure the safe execution of untrusted codes. Monitors observe and transform the execution of these codes, responding when needed to correct or prevent a violation of a user-defined security policy. Prior research has shown that the set of properties monitors can enforce correlates with the latitude they are given to transform and alter the target execution. But for enforcement to be meaningful this capacity must be constrained, otherwise the monitor can enforce any property, but not necessarily in a manner that is useful or desirable. However, such constraints have not been significantly addressed in prior work. In this article, we develop a new paradigm of security policy enforcement in which the behavior of the enforcement mechanism is restricted to ensure that valid aspects present in the execution are preserved notwithstanding any transformation it may perform. These restrictions capture the desired behavior of valid executions of the program, and are stated by way of a preorder over sequences. The resulting model is closer than previous ones to what would be expected of a real-life monitor, from which we demand a minimal footprint on both valid and invalid executions. We illustrate this framework with examples of real-life security properties. Since several different enforcement alternatives of the same property are made possible by the flexibility of this type of enforcement, our study also provides metrics that allow the user to compare monitors objectively and choose the best enforcement paradigm for a given situation.<\/jats:p>","DOI":"10.1145\/2240276.2240281","type":"journal-article","created":{"date-parts":[[2012,8,1]],"date-time":"2012-08-01T17:35:16Z","timestamp":1343842516000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["Corrective Enforcement"],"prefix":"10.1145","volume":"15","author":[{"given":"Rapha\u00ebl","family":"Khoury","sequence":"first","affiliation":[{"name":"Universit\u00e9 Laval"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nadia","family":"Tawbi","sequence":"additional","affiliation":[{"name":"Universit\u00e9 Laval"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,7]]},"reference":[{"key":"e_1_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1016\/0020-0190(85)90056-0"},{"volume-title":"Proceedings of the Workshop on Foundations of Computer Security (FCS).","author":"Bauer L.","key":"e_1_2_2_2_1"},{"key":"e_1_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2009.06.037"},{"key":"e_1_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-011-0137-2"},{"key":"e_1_2_2_5_1","article-title":"Iterative enforcement by suppression: Towards practical enforcement theories","author":"Bielova N.","year":"2011","journal-title":"J. Comput. Secur. To appear."},{"volume-title":"Proceedings of the International Symposium on Engineering Secure Software and Systems. 73--86","author":"Bielova N.","key":"e_1_2_2_6_1"},{"key":"e_1_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/3089844.3089866"},{"volume-title":"Proceedings of the 8th National Computer Security Conference.","author":"Boebert W. E.","key":"e_1_2_2_8_1"},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. 206--214","author":"Brewer D. F. C.","key":"e_1_2_2_9_1"},{"key":"e_1_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.5555\/3089844.3089870"},{"key":"e_1_2_2_11_1","doi-asserted-by":"crossref","unstructured":"Chang E. Manna Z. and Pnueli A. 1991. The safety-progress classification. In Logic and Algebra of Specifications F. Bauer W. Brauer and H. Schwichtenberg Eds. Springer-Verlag 143--202. Chang E. Manna Z. and Pnueli A. 1991. The safety-progress classification. In Logic and Algebra of Specifications F. Bauer W. Brauer and H. Schwichtenberg Eds. Springer-Verlag 143--202.","DOI":"10.1007\/978-3-642-58041-3_5"},{"key":"e_1_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/11513988_36"},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. 246--255","author":"Erlingsson U.","key":"e_1_2_2_13_1"},{"key":"e_1_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89862-7_3"},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2004.1301314"},{"key":"e_1_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1111596.1111601"},{"key":"e_1_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1929529.1929537"},{"key":"e_1_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSSE.2008.1254"},{"volume-title":"Proceedings of the 7th International Workshop on Formal Aspects of Security &amp; Trust (FAST).","author":"Khoury R.","key":"e_1_2_2_19_1"},{"volume-title":"Proceedings of the 5th International Conference Mathematical Methods, Models, and Architectures for Computer Networks Security.","author":"Khoury R.","key":"e_1_2_2_20_1"},{"key":"e_1_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1571-0661(04)80578-4"},{"key":"e_1_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/11916277_21"},{"key":"e_1_2_2_23_1","first-page":"1","article-title":"Edit automata: Enforcement mechanisms for run-time security policies","volume":"4","author":"Ligatti J.","year":"2004","journal-title":"Intern. J. Inform. Secur."},{"key":"e_1_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/11555827_21"},{"key":"e_1_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455526.1455532"},{"volume-title":"Proceedings of the European Symposium on Research in Computer Security (ESORICS).","author":"Ligatti J.","key":"e_1_2_2_26_1"},{"key":"e_1_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1955.tb03788.x"},{"key":"e_1_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03007-9_12"},{"key":"e_1_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/353323.353382"},{"volume-title":"Proceedings of the 22nd National Information Systems Security Conference.","author":"Sobel A. E. K.","key":"e_1_2_2_30_1"},{"key":"e_1_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.5555\/647269.721853"},{"key":"e_1_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ic.2007.07.009"},{"key":"e_1_2_2_33_1","unstructured":"Viswanathan M. 2000. Foundations for the run-time analysis of software systems. Ph.D. thesis University of Pennsylvania. Viswanathan M. 2000. Foundations for the run-time analysis of software systems. Ph.D. thesis University of Pennsylvania."},{"volume-title":"Proceedings of the 9th National Computer Security Conference.","author":"Young W.","key":"e_1_2_2_34_1"},{"key":"e_1_2_2_35_1","unstructured":"Zhu G. Tyagi A. and Roop P. 2006. Stream automata as run-time monitors for open system security policies. Tech. rep. 06-101 Department of Electrical and Computer Engineering Iowa State University Ames Iowa. Zhu G. Tyagi A. and Roop P. 2006. Stream automata as run-time monitors for open system security policies. Tech. rep. 06-101 Department of Electrical and Computer Engineering Iowa State University Ames Iowa."}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2240276.2240281","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2240276.2240281","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:20:52Z","timestamp":1750238452000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2240276.2240281"}},"subtitle":["A New Paradigm of Security Policy Enforcement by Monitors"],"short-title":[],"issued":{"date-parts":[[2012,7]]},"references-count":35,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2012,7]]}},"alternative-id":["10.1145\/2240276.2240281"],"URL":"https:\/\/doi.org\/10.1145\/2240276.2240281","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"type":"print","value":"1094-9224"},{"type":"electronic","value":"1557-7406"}],"subject":[],"published":{"date-parts":[[2012,7]]},"assertion":[{"value":"2011-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-04-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}