USIFES

The groups of Professor Atkinson (Software Engineering), Prof. Mรคdche (Enterprise Information Systems) and Prof. Freiling (Dependable Distributed Systems) have received funding from the DFG for the project USIFES (User-centric, Secure Information Flow Management in Enterprise Systems). This will address the increasing threat to data security resulting from the complexity of networked enterprise information systems and the fact that classical methods of access control are unable to deal with threats that arise from unintentional activities of authorized users. Often undesired information flows result not from malicious attacks but from the interaction of several usage events and information exchanges that, on their own, appear to be quite harmless. Together, however, they break the security policy of the system. USIFES therefore focuses on controlling undesired information flow at the interface between system and user. The project will develop a technique to identify, model, and protect against undesirable information flows resulting from the interplay between human-computer, human-human and computer-computer interactions.