Tracking Information Flow via Delayed Output:

Addressing Privacy in IoT and Emailing Apps


Iulia Bastys, Frank Piessens, and Andrei Sabelfeld</br> In Proceedings of the 23rd Nordic Conference on Secure IT Systems (NordSec), Oslo, Norway, 28-30 November 2018.

Abstract: This paper focuses on tracking information flow in the presence of delayed output. We motivate the need to address delayed output in the domains of IoT apps and email marketing. We discuss the threat of privacy leaks via delayed output in code published by malicious app makers on popular IoT app platforms. We discuss the threat of privacy leaks via delayed output in non-malicious code on popular platforms for email-driven marketing. We present security characterizations of projected noninterference and projected weak secrecy to capture information flows in the presence of delayed output in malicious and non-malicious code, respectively. We develop two security type systems: for information flow control in potentially malicious code and for taint tracking in non-malicious code, engaging read and write security types to soundly enforce projected noninterference and projected weak secrecy.

Download the full paper. </div> </body>