On-the-fly inlining of dynamic security monitors

On-the-fly inlining of dynamic security monitors
复制标题

动态安全监视器的动态内联

DOI:
10.1007/978-3-642-15257-3_16
复制
发表时间:
2010
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
A. Sabelfeld
A. Sabelfeld
中科院分区:
--
文献类型:
--
作者:
Jonas Magazinius;Alejandro Russo;A. Sabelfeld

文献摘要

参考文献

被引文献

相似文献

我们如何保证可能源自第三方的代码不会危害基础申请的安全性?基于语言的信息流安全考虑了以不同敏感性级别操纵数据的程序。确保此类程序中的信息流仍然是一个公开挑战。最近,在了解安全信息流动的动态监控方面取得了长足的进步。本文提出了一个框架,用于包含动态信息流监视器。我们框架的一个新颖特征是能够即时执行内线。我们考虑一种源语言,其中包括对字符串的动态代码评估,其内容在运行时可能才知道。为了确保此构建体,我们的内联是在字符串评估时即时完成的,就像常规的离线内线一样,不需要修改托管运行时环境。我们提出了一种简单语言的forma!lization,以表明嵌入式代码是安全的:它满足了非干扰属性。我们还讨论了基于手动和自动代码重写的实验结果的实际考虑。
How do we guarantee that a piece of code, possibly originating from third party, does not jeopardize the security of the underlying application? Language-based information-flow security considers programs that manipulate pieces of data at different sensitivity levels. Securing information flow in such programs remains an open challenge. Recently, considerable progress has been made on understanding dynamic monitoring for secure information flow. This paper presents a framework for inlining dynamic information-flow monitors. A novel feature of our framework is the ability to perform inlining on the fly. We consider a source language that includes dynamic code evaluation of strings whose content might not be known until runtime. To secure this construct, our inlining is done on the fly, at the string evaluation time, and, just like conventional offline inlining, requires no modification of the hosting runtime environment. We present a forma!lization for a simple language to show that the inlined code is secure: it satisfies a non-interference property. We also discuss practical considerations experimental results based on both manual and automatic code rewriting.
基于语言的不可信 JavaScript 隔离
DOI: 10.1109/csf.2009.11
发表时间: 2009
期刊: --
影响因子: --
作者:
Maffeis S
通讯作者: Maffeis S