Declarative, Temporal, and Practical Programming with Capabilities

Declarative, Temporal, and Practical Programming with Capabilities
复制标题

具有声明式、临时性和实用编程功能

DOI:
--
复制
发表时间:
2013
期刊:
IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
R. Watson
R. Watson
中科院分区:
--
文献类型:
--
作者:
William R. Harris;S. Jha;T. Reps;Jonathan Anderson;R. Watson

文献摘要

被引文献

相似文献

新的操作系统(例如Capsicum功能系统)允许程序员编写一个应用程序,该应用程序通过在程序中的几个关键点调用特定于安全性的系统调用来满足强大的安全属性。但是,重写一个应用程序正确调用的应用程序是一个容易出错的过程:即使是Capsicum开发人员也报告了重写程序以正确调用系统调用的困难。本文介绍了CapWeave,该工具是输入(i)LLVM程序,以及(ii)程序在执行过程中必须具有的可能改变功能的声明性政策,并将程序重写以使用capsicum System呼叫的程序来使用Capsicum System呼叫到执行该政策。我们的实验表明,可以将CAPWEAVE应用于重写至关重要的UNIX实用程序以满足实际的安全策略。 Capweave本身可以迅速工作,并且在Capweave生产的程序中产生的运行时开销通常对于实际工作量而言通常很低。
New operating systems, such as the Capsicum capability system, allow a programmer to write an application that satisfies strong security properties by invoking security-specific system calls at a few key points in the program. However, rewriting an application to invoke such system calls correctly is an error-prone process: even the Capsicum developers have reported difficulties in rewriting programs to correctly invoke system calls. This paper describes capweave, a tool that takes as input (i) an LLVM program, and (ii) a declarative policy of the possibly-changing capabilities that a program must hold during its execution, and rewrites the program to use Capsicum system calls to enforce the policy. Our experiments demonstrate that capweave can be applied to rewrite security-critical UNIX utilities to satisfy practical security policies. capweave itself works quickly, and the runtime overhead incurred in the programs that capweave produces is generally low for practical workloads.