<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en"><front><journal-meta><journal-id journal-id-type="publisher-id">Programming and Computer Software</journal-id><journal-title-group><journal-title xml:lang="en">Programming and Computer Software</journal-title><trans-title-group xml:lang="ru"><trans-title>Программирование</trans-title></trans-title-group></journal-title-group><issn publication-format="print">0132-3474</issn><issn publication-format="electronic">3034-5847</issn><publisher><publisher-name xml:lang="en">The Russian Academy of Sciences</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">695670</article-id><article-id pub-id-type="doi">10.7868/S3034584725040079</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>INFORMATION SECURITY</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>ИНФОРМАЦИОННАЯ БЕЗОПАСНОСТЬ</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">PLIF PLATFORM: MODELING AND VERIFICATION OF INFORMATION FLOWS IN SOFTWARE DB UNITS USING THE TEMPORAL LOGIC OF ACTIONS TLA+</article-title><trans-title-group xml:lang="ru"><trans-title>Платформа PLIF: моделирование и проверка информационных потоков в программных блоках баз данных с использованием аппарата темпоральной логики действий TLA+</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Timakov</surname><given-names>A. A.</given-names></name><name xml:lang="ru"><surname>Тимаков</surname><given-names>А. А.</given-names></name></name-alternatives><email>timakov@mirea.ru</email><xref ref-type="aff" rid="aff1"/></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Ryzhov</surname><given-names>I. G.</given-names></name><name xml:lang="ru"><surname>Рыжов</surname><given-names>И. Г.</given-names></name></name-alternatives><email>ryzhov.ilgen@gmail.com</email><xref ref-type="aff" rid="aff2"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="en">MIREA – Russian Technological University</institution></aff><aff><institution xml:lang="ru">МИРЭА – Российский технологический универсистет</institution></aff></aff-alternatives><aff-alternatives id="aff2"><aff><institution xml:lang="en">RUDN University</institution></aff><aff><institution xml:lang="ru">Российский универсистет дружбы народов</institution></aff></aff-alternatives><pub-date date-type="pub" iso-8601-date="2025-08-15" publication-format="electronic"><day>15</day><month>08</month><year>2025</year></pub-date><issue>4</issue><issue-title xml:lang="en">NO4 (2025)</issue-title><issue-title xml:lang="ru">№4 (2025)</issue-title><fpage>83</fpage><lpage>98</lpage><history><date date-type="received" iso-8601-date="2025-11-01"><day>01</day><month>11</month><year>2025</year></date></history><permissions><copyright-statement xml:lang="en">Copyright ©; 2025, Russian Academy of Sciences</copyright-statement><copyright-statement xml:lang="ru">Copyright ©; 2025, Российская академия наук</copyright-statement><copyright-year>2025</copyright-year><copyright-holder xml:lang="en">Russian Academy of Sciences</copyright-holder><copyright-holder xml:lang="ru">Российская академия наук</copyright-holder><ali:free_to_read xmlns:ali="http://www.niso.org/schemas/ali/1.0/" start_date="2026-08-31"/></permissions><self-uri xlink:href="https://transsyst.ru/0132-3474/article/view/695670">https://transsyst.ru/0132-3474/article/view/695670</self-uri><abstract xml:lang="en"><p>The verification of software properties using formal verification tools is one of the current research directions in the field of information flow control. Security conditions of information flows in software under various information noninterferrence schemes are naturally described by so-called hyper-properties in well-known extensions of linear temporal logic and computation tree logic. In practice, verifying such properties for large projects is a non-trivial task. In this work, the authors translate the idea of dynamic type checking to detect prohibited information flows into the realm of computation verification using model-checking tools. Computations over security labels (safe types) are described by the abstract semantics of information flows. Transitioning from concrete computational semantics to abstract semantics of information flows allows formulating these security properties as state properties. In this case, proven tools in large industrial projects such as TLA+ and TLC can be used for the description and verification of real computer systems.</p></abstract><trans-abstract xml:lang="ru"><p>Проверка свойств программного обеспечения с использованием инструментов формальной верификации является одним из текущих направлений исследований в области контроля информационных потоков. Условия безопасности информационных потоков в программном обеспечении в различных схемах информационного невлияния естественным образом описываются так называемыми гипер-свойствами в известных расширениях линейной темпоральной логики и логики ветвящегося времени. На практике проверка таких свойств для больших проектов является нетривиальной задачей. В работе авторы транслируют идею динамической проверки типов для выявления запрещенных информационных потоков в область проверки вычислений с использованием инструментов проигрывания моделей. Вычисления над метками безопасности (безопасными типами) описываются абстрактной семантикой информационных потоков. Переход от конкретной вычислительной семантики к абстрактной семантике информационных потоков позволяет сформулировать указанные свойства безопасности как свойства состояний, в этом случае для описания и проверки реальных компьютерных систем могут быть использованы зарекомендовавшие себя в крупных промышленных проектах инструменты TLA+ и TLC.</p></trans-abstract><kwd-group xml:lang="en"><kwd>information flow</kwd><kwd>information flow control</kwd><kwd>security policy language</kwd><kwd>formal verification</kwd><kwd>model checking</kwd><kwd>temporal logic</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>информационный поток</kwd><kwd>управление информационным потоком</kwd><kwd>язык политики безопасности</kwd><kwd>формальная верификация</kwd><kwd>проверка модели</kwd><kwd>темпоральная логика</kwd></kwd-group></article-meta></front><body></body><back><ref-list><ref id="B1"><label>1.</label><mixed-citation>Timakov A.А. Analysis of information flow security using software implementing business logic based on stored database program blocks. Russian Technological Journal. 2024. V. 12. № 2. P. 16–27.</mixed-citation></ref><ref id="B2"><label>2.</label><mixed-citation>Тимаков А.А. PLIF. 2021. GitHub. https://github.com / timimin / plif</mixed-citation></ref><ref id="B3"><label>3.</label><mixed-citation>Kozyri E. et al. Expressing Information Flow Properties // Foundations and Trends® in Privacy and Security. 2022. V. 3. № 1. P. 1–102.</mixed-citation></ref><ref id="B4"><label>4.</label><mixed-citation>Hedin D., Sabelfeld A. A Perspective on Information-Flow Control // Software safety and security. 2012. P. 319–347.</mixed-citation></ref><ref id="B5"><label>5.</label><mixed-citation>Balliu M., Schoepe D., Sabelfeld A. We are family: Relating information-flow trackers // Computer Security – ESORICS 2017: 22nd European Symposium on Research in Computer Security, Oslo, Norway, September 11–15, 2017, Proceedings, Part I 22. Springer International Publishing. 2017. P. 124–145.</mixed-citation></ref><ref id="B6"><label>6.</label><mixed-citation>Russo A., Sabelfeld A., Li K. Implicit flows in malicious and nonmalicious code // Logics and Languages for Reliability and Security. – IOS Press, 2010. P. 301–322.</mixed-citation></ref><ref id="B7"><label>7.</label><mixed-citation>Jang D. et al. An empirical study of privacy-violating information flows in JavaScript web applications // Proceedings of the 17th ACM conference on Computer and communications security. 2010. P. 270–283.</mixed-citation></ref><ref id="B8"><label>8.</label><mixed-citation>Kang M.G. et al. Dta++: dynamic taint analysis with targeted control-flow propagation // NDSS. 2011.</mixed-citation></ref><ref id="B9"><label>9.</label><mixed-citation>King D. et al. Implicit flows: Can’t live with ‘em, can’t live without ‘em // Information Systems Security: 4th International Conference, ICISS 2008, Hyderabad, India, December 16–20, 2008. Proceedings 4. Springer Berlin Heidelberg, 2008. P. 56–70.</mixed-citation></ref><ref id="B10"><label>10.</label><mixed-citation>Staicu C.A. et al. An empirical study of information flows in real-world javascript // Proceedings of the 14th ACM SIGSAC Workshop on Programming Languages and Analysis for Security. 2019. P. 45–59.</mixed-citation></ref><ref id="B11"><label>11.</label><mixed-citation>Myers C.A., Liskov B. A decentralized model for information flow control // ACM SIGOPS Operating Systems Review. 1997. № 5. P. 129–142.</mixed-citation></ref><ref id="B12"><label>12.</label><mixed-citation>Broberg N., van Delft B., Sands D. Paragon for practical programming with information-flow control // Programming Languages and Systems: 11th Asian Symposium, APLAS 2013, Melbourne, VIC, Australia, December 9–11, 2013. Proceedings 11. Springer International Publishing. 2013. P. 217–232.</mixed-citation></ref><ref id="B13"><label>13.</label><mixed-citation>Pottier F., Simonet V. Information Flow Inference for ML // ACM Transactions on Programming Languages and Systems. 2003. P. 117–158.</mixed-citation></ref><ref id="B14"><label>14.</label><mixed-citation>Volpano D., Irvine C., Smith G. Sound type system for secure flow analysis // Journal of Computer Security. 1996. № 2–3. P. 167–187.</mixed-citation></ref><ref id="B15"><label>15.</label><mixed-citation>Clarkson M.R. et al. Temporal logics for hyperproperties // Principles of Security and Trust: Third International Conference, POST 2014, Held as Part of the European Joint Conferences on Theory and Practice of Software, ETAPS 2014, Grenoble, France, April 5–13. 2014. Proceedings 3. Springer Berlin Heidelberg. 2014. P. 265–284.</mixed-citation></ref><ref id="B16"><label>16.</label><mixed-citation>Spearritt J. // Thesis for the Degree of Doctor of Engineering Practical. The Applicability of Information Flow to Secure Java Development, 2017.</mixed-citation></ref><ref id="B17"><label>17.</label><mixed-citation>Seifermann S. et al. Detecting violations of access control and information flow policies in data flow diagrams // Journal of Systems and Software. 2022. V. 184. P. 111138.</mixed-citation></ref><ref id="B18"><label>18.</label><mixed-citation>Methni A., Lemerre M., Hedia B.B., Barkaoui K., Haddad S. An Approach for Verifying Concurrent C Programs // 8th Junior Researcher Workshop on Real-Time Computing. 2014. P. 33–36.</mixed-citation></ref><ref id="B19"><label>19.</label><mixed-citation>Lamport L. Specifying systems: the TLA+ language and tools for hardware and software engineers. 2002.</mixed-citation></ref><ref id="B20"><label>20.</label><mixed-citation>Becker S., Koziolek H., Reussner R. The Palladio component model for model-driven performance prediction // Journal of Systems and Software. 2009. V. 82. № 1. P. 3–22.</mixed-citation></ref><ref id="B21"><label>21.</label><mixed-citation>Dura A., Reichenbach C., Sŏderberg E. JavaDL: automatically incrementalizing Java bug pattern detection // Proceedings of the ACM on Programming Languages. 2021. V. 5. № OOPSLA. P. 1–31.</mixed-citation></ref><ref id="B22"><label>22.</label><mixed-citation>Leavens G.T., Baker A.L., Ruby C. JML: a Java modeling language // Formal Underpinnings of Java Workshop (at OOPSLA’98). 1998. P. 404–420.</mixed-citation></ref><ref id="B23"><label>23.</label><mixed-citation>Harel D., Kozen D., Tiuryn J. Dynamic logic // ACM SIGACT News. 2001. V. 32. № 1. P. 66–69.</mixed-citation></ref><ref id="B24"><label>24.</label><mixed-citation>Ahrendt W. et al. The KeY platform for verification and analysis of Java programs // Verified Software: Theories, Tools and Experiments: 6th International Conference, VSTTE 2014, Vienna, Austria, July 17–18, 2014, Revised Selected Papers 6. Springer International Publishing. 2014. P. 55–71.</mixed-citation></ref><ref id="B25"><label>25.</label><mixed-citation>DeMarco T. Structured analysis and system specification. Software pioneers: contributions to software engineering. Berlin, Heidelberg: Springer Berlin Heidelberg. 2011. P. 529–560.</mixed-citation></ref></ref-list></back></article>
