The high-level benefits of low-level sandboxing

The high-level benefits of low-level sandboxing
复制标题

DOI:
10.1145/3371100
复制
发表时间:
2019-12
影响因子:
--
通讯作者:
Michael Sammler;D. Garg;Derek Dreyer;Tadeusz Litak
Michael Sammler;D. Garg;Derek Dreyer;Tadeusz Litak
中科院分区:
--
文献类型:
--
作者:
Michael Sammler;D. Garg;Derek Dreyer;Tadeusz Litak

文献摘要

被引文献

相似文献

沙箱是一种常见的技术,允许低级,不信任的组件可以安全地与受信任的代码进行安全互动。沙箱提供了本文,我们通过表明沙箱可以填补这一空白,即使在有任意信任的代码的情况下,也可以提出可信度的稳健安全概念。将信任代码与不信任的代码相结合的语言是理想的操作语义。 ,只要在“任何”类型上出现所有与不信任代码的交互(所有价值观都居住的类型),以减轻必须仅在“任何”类型的情况下与不受信任的代码进行互动的燃烧,我们就会形式化并证明安全的几种包装器,它们会在“任何”类型和更丰富的类型之间自动转换值。
Sandboxing is a common technique that allows low-level, untrusted components to safely interact with trusted code. However, previous work has only investigated the low-level memory isolation guarantees of sandboxing, leaving open the question of the end-to-end guarantees that sandboxing affords programmers. In this paper, we fill this gap by showing that sandboxing enables reasoning about the known concept of robust safety, i.e., safety of the trusted code even in the presence of arbitrary untrusted code. To do this, we first present an idealized operational semantics for a language that combines trusted code with untrusted code. Sandboxing is built into our semantics. Then, we prove that safety properties of the trusted code (as enforced through a rich type system) are upheld in the presence of arbitrary untrusted code, so long as all interactions with untrusted code occur at the “any” type (a type inhabited by all values). Finally, to alleviate the burden of having to interact with untrusted code at only the “any” type, we formalize and prove safe several wrappers, which automatically convert values between the “any” type and much richer types. All our results are mechanized in the Coq proof assistant.