attacker has knowledge about public identifiers. On the other hand the red dottedline shows the global declassification policy represented by a predicate . As longas the solid line remains below the dotted line the declassification is safe, namelythe attacker knowledge is smaller than the information released intentionally priorto program execution. In this case, one can see that after the second observationpoint o2 the attacker learns more than the policy allows, thus the program becomesinsecure.
đang được dịch, vui lòng đợi..
