SIF: Enforcing Confidentiality and Integrity in Web Applications

SIF: Enforcing Confidentiality and Integrity in Web Applications
复制标题

SIF:加强 Web 应用程序的机密性和完整性

DOI:
--
复制
发表时间:
2007
期刊:
USENIX Security Symposium
影响因子:
--
通讯作者:
A. Myers
A. Myers
中科院分区:
--
文献类型:
--
作者:
Stephen Chong;K. Vikram;A. Myers

文献摘要

被引文献

相似文献

SIF(Servlet Information Flow)是一种用于构建高保证Web应用程序的新型软件框架,使用基于语言的信息流控制来加强安全性。显式的、端到端的机密性和完整性策略可以作为编译时程序注释或运行时用户需求给出。实时和运行时检查可以有效地执行这些策略。众所周知,信息流分析对SQL注入和跨站点脚本编写很有用,但SIF更普遍地防止了信息的不适当使用:流向客户端的机密信息受到控制,来自客户端的低完整性信息也受到控制。表达性策略允许用户和应用程序提供商保护信息不受彼此影响。 SIF将信任从Web应用程序中移到框架和编译器中。这为应用程序部署人员提供了更强的安全保证。 基于网络的信息流保证了廉价、强大的信息安全。但到目前为止,它还不能有效地在高度动态的应用程序中实施信息安全。为了构建SIF,我们开发了新的语言功能,使编写逼真的Web应用程序成为可能。通过适度的执行开销获得了更高的保证。
SIF (Servlet Information Flow) is a novel software framework for building high-assurance web applications, using language-based information-flow control to enforce security. Explicit, end-to-end confidentiality and integrity policies can be given either as compile-time program annotations, or as run-time user requirements. Compile-time and run-time checking efficiently enforce these policies. Information flow analysis is known to be useful against SQL injection and cross-site scripting, but SIF prevents inappropriate use of information more generally: the flow of confidential information to clients is controlled, as is the flow of low-integrity information from clients. Expressive policies allow users and application providers to protect information from one another. SIF moves trust out of the web application, and into the framework and compiler. This provides application deployers with stronger security assurance. Language-based information flow promises cheap, strong information security. But until now, it could not effectively enforce information security in highly dynamic applications. To build SIF, we developed new language features that make it possible to write realistic web applications. Increased assurance is obtained with modest enforcement overhead.