Safer at any speed: automatic context-aware safety enhancement for Rust

Safer at any speed: automatic context-aware safety enhancement for Rust
复制标题

在任何速度下都更安全:Rust 的自动上下文感知安全增强

DOI:
10.1145/3485480
复制
发表时间:
2021
影响因子:
--
通讯作者:
Levy, Amit
Levy, Amit
中科院分区:
--
文献类型:
--
作者:
Popescu, Natalie;Xu, Ziyang;Apostolakis, Sotiris;August, David I.;Levy, Amit

文献摘要

参考文献

被引文献

相似文献

类型安全语言通过构造消除了所有类别的漏洞,如缓冲区溢出,从而提高了应用程序的安全性。然而,这种安全性有时是以性能为代价的。因此,许多现代类型安全语言都提供了转义门,允许开发人员手动绕过它们。性能与安全的相对值和获得的性能程度取决于应用程序环境,包括用户目标和要在其上执行应用程序的硬件。由于库可以在许多不同的环境中使用,库开发人员不能做出适用于所有情况的安全与性能权衡决定。应用程序开发人员可以自己调优库以提高安全性或性能,但这需要额外的工作,并且会降低库的可重用性。为了解决这个问题,我们提出了一个Rust开发工具Nader,它根据开发人员的偏好和应用程序上下文自动将不安全的代码转换为等价的安全代码,从而使应用程序更加安全。在给定环境下的端到端系统评估中,Nader自动重新引入许多库边界检查,在许多情况下使使用常用Rust库的应用程序代码更安全,而不会造成相应的性能损失。
Type-safe languages improve application safety by eliminating whole classes of vulnerabilities–such as buffer overflows–by construction. However, this safety sometimes comes with a performance cost. As a result, many modern type-safe languages provide escape hatches that allow developers to manually bypass them. The relative value of performance to safety and the degree of performance obtained depends upon the application context, including user goals and the hardware upon which the application is to be executed. Since libraries may be used in many different contexts, library developers cannot make safety-performance trade-off decisions appropriate for all cases. Application developers can tune libraries themselves to increase safety or performance, but this requires extra effort and makes libraries less reusable. To address this problem, we present NADER, a Rust development tool that makes applications safer by automatically transforming unsafe code into equivalent safe code according to developer preferences and application context. In end-to-end system evaluations in a given context, NADER automatically reintroduces numerous library bounds checks, in many cases making application code that uses popular Rust libraries safer with no corresponding loss in performance.
乳蛋饼
DOI: --
发表时间: 2021
期刊: Petit Propos Culinaires
影响因子: --
作者:
William Sayers
通讯作者: William Sayers
DOI: --
发表时间: 2007
期刊: Principles and Practice of Programming in Java
影响因子: --
作者:
Thomas Würthinger;Christian Wimmer;H. Mössenböck
通讯作者: H. Mössenböck
安全哈斯克尔
DOI: --
发表时间: 2013
期刊: ACM SIGPLAN Symposium/Workshop on Haskell
影响因子: --
作者:
David Terei;S. Marlow;S. Jones;David Mazières
通讯作者: David Mazières
DOI: --
发表时间: 2018-10
期刊: --
影响因子: --
作者:
C. Kulkarni;S. Moore;Mazhar Naqvi;Tian Zhang;R. Ricci;Ryan Stutsman
通讯作者: C. Kulkarni;S. Moore;Mazhar Naqvi;Tian Zhang;R. Ricci;Ryan Stutsman
程序员如何使用不安全的 Rust?
DOI: --
发表时间: 2020
期刊: Proc. ACM Program. Lang.
影响因子: --
作者:
Vytautas Astrauskas;Christoph Matheja;F. Poli;Peter Müller;Alexander J. Summers
通讯作者: Alexander J. Summers