This document summarizes a research paper that proposes a new information flow control model called WSIFC (Web Service Information Flow Control) to dynamically prevent information leakage for web services. WSIFC is based on a lattice model and uses security levels and tags to monitor and control flows of sensitive information during web service execution. It aims to reduce the runtime overhead of previous information flow control models for web services while still preventing information leakage. The key concepts of WSIFC including sensitive variables, screens, files, security levels, tags, and rules for controlling information flows are defined and explained.
Related topics: