Collaborative Research: Integrating Pointer Confinement and Access Control for Encapsulation
协作研究:集成指针限制和访问控制进行封装
基本信息
- 批准号:0208984
- 负责人:
- 金额:$ 16万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2002
- 资助国家:美国
- 起止时间:2002-09-01 至 2006-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
In modern computer systems, computation is distributed over many host machines. Mutually untrusted machines and users coexist, and software is built using plug-and-play components downloaded from remote hosts. Multiple users share resources so it is critical to ensure, e.g., that private information is not compromised. Languages like Java and C# are designed to provide such security by enforcing encapsulation boundaries that restrict interdependencies and information flows between program components. Such boundaries are undercut, however, by ubiquitous pointer aliasing which can be maliciously exploited to leak sensitive information.This project studies ways to confine pointers to their intended scopes. The focus is on the interplay between static analysis and dynamic access control to achieve confinement. The technical goal is to find confinement regimes that can be used to assure secure information flow in systems implemented using dynamic binding, multithreading, inheritance, class-based encapsulation, and access control. Analyses and transformations to minimize run-time performance costs for confinement and access control are also investigated. This work will lead to better programming methods and tools for development of web-based services and other distributed applications that require a high level of assurance. The work will contribute to technology for implementing programming languages and for checking for security flaws in application programs.
在现代计算机系统中,计算分布在许多主机上。相互不信任的机器和用户共存,软件是使用从远程主机下载的即插即用组件构建的。多个用户共享资源,因此必须确保,例如,私人信息不会被泄露 像Java和C#这样的语言旨在通过强制封装边界来提供这种安全性,这些边界限制程序组件之间的相互依赖性和信息流。 然而,这种边界被无处不在的指针别名所削弱,指针别名可以被恶意利用来泄漏敏感信息。本项目研究将指针限制在其预期范围内的方法。 重点是静态分析和动态访问控制之间的相互作用,以实现限制。 技术目标是找到可用于确保使用动态绑定、多线程、继承、基于类的封装和访问控制实现的系统中的安全信息流的限制机制。 分析和转换,以尽量减少运行时的性能成本限制和访问控制也进行了研究。 这项工作将导致更好的编程方法和工具,用于开发基于网络的服务和其他需要高水平保证的分布式应用程序。 这项工作将有助于实现编程语言和检查应用程序中的安全缺陷的技术。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
David Naumann其他文献
Association between Center Volume and Allocation to Curative Surgery and Long-Term Survival for Retroperitoneal Sarcoma
- DOI:
10.1016/j.ejso.2022.11.141 - 发表时间:
2023-02-01 - 期刊:
- 影响因子:
- 作者:
Sivesh Kamarajah;Marco Baia;David Naumann;Fahad Mahmood;Alessandro Parente;Max Almond;Fabio Tirotta;Samuel Ford;Fadi Dahdaleh;Anant Desai - 通讯作者:
Anant Desai
Does pre-operative neoadjuvant systemic therapy affect the number of lymph nodes on histological examination of tissues excised during axillary node clearance surgery?
- DOI:
10.1016/j.ejso.2012.02.064 - 发表时间:
2012-05-01 - 期刊:
- 影响因子:
- 作者:
David Naumann;Martin Sintler - 通讯作者:
Martin Sintler
Preconceptions, experience and future expectations of patients undergoing robotic colorectal surgery at a single centre
- DOI:
10.1016/j.ejso.2019.11.170 - 发表时间:
2020-02-01 - 期刊:
- 影响因子:
- 作者:
Mariam Baig;Neena Randhawa;David Naumann;Charles Evans;Adeel Bajwa - 通讯作者:
Adeel Bajwa
Systemic review and meta-analysis comparing stapled versus hand-sewn anastomoses following emergency bowel resection
- DOI:
10.1016/j.ijsu.2014.07.096 - 发表时间:
2014-11-01 - 期刊:
- 影响因子:
- 作者:
David Naumann;Aneel Bhangu;Michael Kelly;Douglas Bowley - 通讯作者:
Douglas Bowley
Are the number of lymph nodes excised during axillary node clearance surgery affected by neoadjuvant chemotherapy?
- DOI:
10.1016/j.ijsu.2012.06.053 - 发表时间:
2012-01-01 - 期刊:
- 影响因子:
- 作者:
David Naumann;Martin Sintler - 通讯作者:
Martin Sintler
David Naumann的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('David Naumann', 18)}}的其他基金
SaTC: CORE: Small: Relational Verification for Information Assurance and Privacy
SaTC:核心:小型:信息保障和隐私的关系验证
- 批准号:
1718713 - 财政年份:2017
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
EAGER: Hyperproperty Abstraction for Information Flow Control
EAGER:信息流控制的超属性抽象
- 批准号:
1649894 - 财政年份:2016
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Flexible and Practical Information Flow Assurance for Mobile Apps
TWC:媒介:协作:灵活实用的移动应用信息流保障
- 批准号:
1228930 - 财政年份:2012
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
SHF: Small: Collaborative Research: Specification Language Foundations for Modular Reasoning Methodologies
SHF:小型:协作研究:模块化推理方法的规范语言基础
- 批准号:
0915611 - 财政年份:2009
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: CRI: CRD: A JML Community Infrastructure --Revitalizing Tools and Documentation to Aid Formal Methods Research
协作研究:CRI:CRD:JML 社区基础设施——振兴工具和文档以帮助形式化方法研究
- 批准号:
0708330 - 财政年份:2007
- 资助金额:
$ 16万 - 项目类别:
Continuing Grant
CT-ISG Collaborative Research: Access Control and Downgrading in Information Flow Assurance
CT-ISG协同研究:信息流保障中的访问控制与降级
- 批准号:
0627338 - 财政年份:2006
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: Formal Methods for Behavioral Subclassing and Callbacks
协作研究:行为子类化和回调的形式化方法
- 批准号:
0429894 - 财政年份:2004
- 资助金额:
$ 16万 - 项目类别:
Continuing Grant
U.S.-Brazil Cooperative Research: Towards a Practical Calculus of Object-Oriented Programming
美国-巴西合作研究:面向对象编程的实用演算
- 批准号:
9813854 - 财政年份:1999
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Program Derivation for a Data Structures Course
数据结构课程的程序推导
- 批准号:
9455660 - 财政年份:1995
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Tools for Undergraduate Program Derivation
本科生程序推导工具
- 批准号:
9451614 - 财政年份:1994
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: BoCP-Implementation: Alpine plants as a model system for biodiversity dynamics in a warming world: Integrating genetic, functional, and community approaches
合作研究:BoCP-实施:高山植物作为变暖世界中生物多样性动态的模型系统:整合遗传、功能和社区方法
- 批准号:
2326020 - 财政年份:2024
- 资助金额:
$ 16万 - 项目类别:
Continuing Grant
Collaborative Research: BoCP-Implementation: Alpine plants as a model system for biodiversity dynamics in a warming world: Integrating genetic, functional, and community approaches
合作研究:BoCP-实施:高山植物作为变暖世界中生物多样性动态的模型系统:整合遗传、功能和社区方法
- 批准号:
2326021 - 财政年份:2024
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: BoCP-Implementation: Integrating Traits, Phylogenies and Distributional Data to Forecast Risks and Resilience of North American Plants
合作研究:BoCP-实施:整合性状、系统发育和分布数据来预测北美植物的风险和恢复力
- 批准号:
2325835 - 财政年份:2024
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: BoCP-Implementation: Integrating Traits, Phylogenies and Distributional Data to Forecast Risks and Resilience of North American Plants
合作研究:BoCP-实施:整合性状、系统发育和分布数据来预测北美植物的风险和恢复力
- 批准号:
2325837 - 财政年份:2024
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: Integrating Optimal Function and Compliant Mechanisms for Ubiquitous Lower-Limb Powered Prostheses
合作研究:将优化功能和合规机制整合到无处不在的下肢动力假肢中
- 批准号:
2344765 - 财政年份:2024
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: BoCP-Implementation: Integrating Traits, Phylogenies and Distributional Data to Forecast Risks and Resilience of North American Plants
合作研究:BoCP-实施:整合性状、系统发育和分布数据来预测北美植物的风险和恢复力
- 批准号:
2325838 - 财政年份:2024
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: Integrating Optimal Function and Compliant Mechanisms for Ubiquitous Lower-Limb Powered Prostheses
合作研究:将优化功能和合规机制整合到无处不在的下肢动力假肢中
- 批准号:
2344766 - 财政年份:2024
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: BoCP-Implementation: Integrating Traits, Phylogenies and Distributional Data to Forecast Risks and Resilience of North American Plants
合作研究:BoCP-实施:整合性状、系统发育和分布数据来预测北美植物的风险和恢复力
- 批准号:
2325836 - 财政年份:2024
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
Collaborative Research: AF: Small: Graph Analysis: Integrating Metric and Topological Perspectives
合作研究:AF:小:图分析:整合度量和拓扑视角
- 批准号:
2310412 - 财政年份:2023
- 资助金额:
$ 16万 - 项目类别:
Standard Grant
IntBIO: Collaborative Research: Phenotypes of the Anthropocene: integrating the consequences of sensory stressors across biological scales
IntBIO:合作研究:人类世的表型:整合跨生物尺度的感觉压力源的后果
- 批准号:
2316364 - 财政年份:2023
- 资助金额:
$ 16万 - 项目类别:
Standard Grant