Journal Home Online First Current Issue Archive For Authors Journal Information 中文版

Frontiers of Information Technology & Electronic Engineering >> 2018, Volume 19, Issue 4 doi: 10.1631/FITEE.1601371

Using information flowanalysis to detect implicit information leaks forweb service composition

. College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China.. Collaborative Innovation Center of Novel Software Technology and Industrialization.

Available online: 2018-06-28

Next Previous

Abstract

Information leak, which can undermine the compliance of web-service-composition business processes for some policies, is one of the major concerns in web service composition. We present an automated and effective approach for the detection of implicit information leaks in business process execution language (BPEL) based on information flow analysis. We introduce an adequate meta-model for BPEL representation based on a Petri net for transformation and analysis. Building on the concept of Petri net place-based noninterference, the core contribution of this paper is the application of a Petri net reachability graph to estimate Petri net interference and thereby to detect implicit information leaks in web service composition. In addition, a case study illustrates the application of the approach on a concrete workflow in BPEL notation.

Related Research