A security technique that monitors which system state can be influenced by untrusted data, regardless of what the model claims.