Joe-E: A Security-Oriented Subset of Java

Joe-E: A Security-Oriented Subset of Java
复制标题

DOI:
--
复制
发表时间:
2010
期刊:
--
影响因子:
--
通讯作者:
A. Mettler;D. Wagner;T. Close
A. Mettler;D. Wagner;T. Close
中科院分区:
其他
文献类型:
--
作者:
A. Mettler;D. Wagner;T. Close

文献摘要

被引文献

相似文献

我们提出了Joe-E,旨在支持安全软件系统的开发将特定的特权的原理应用于应用程序特定的参考监测器,无法介绍和使用特定于域的安全性摘要;展示如何在保留主流对象的语言的功能和感觉的同时,达到对象能力语言的强大安全性。与以前的对象相关性语言相比,在本文中依靠运行时检查的安全性属性Joe-e可用于开发具有新型安全属性的系统,这些系统难以确保否则,包括提供透明,交易对象持久性的Web应用程序平台,并可以安全地托管单个JVM中的多个相互构成的应用程序。
We present Joe-E, a language designed to support the development of secure software systems. Joe-E is a subset of Java that makes it easier to architect and implement programs with strong security properties that can be checked during a security review. It enables programmers to apply the principle of least privilege to their programs; implement application-specific reference monitors that cannot be bypassed; introduce and use domain-specific security abstractions; safely execute and interact with untrusted code; and build secure, extensible systems. Joe-E demonstrates how it is possible to achieve the strong security properties of an object-capability language while retaining the features and feel of a mainstream object-oriented language. Additionally, we present ways in which Java’s static type safety complements object-capability analysis and permits additional security properties to be verified statically, compared with previous object-capability languages which rely on runtime checks. In this paper, we describe the design and implementation of Joe-E and its advantages for security and auditability over standard Java. We demonstrate how Joe-E can be used to develop systems with novel security properties that would be difficult or impossible to ensure otherwise, including a web application platform that provides transparent, transactional object persistence and can safely host multiple mutually-distrustful applications in a single JVM.