Certified Verification of Client-Side Web Programs
Certified Verification of Client-Side Web Programs
批准号:
EP/K032089/1
负责人:
Philippa Gardner
金额:
$113.9万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2013
资助国家:
英国
项目状态:
已结题
起止时间:
2013 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The Web is evolving at enormous speed from a collection of mainlystatic web pages to the current huge dynamic ecosystem where theboundary between web pages and software application has becomeindistinct (e.g. Google maps). This effect is so pronounced thatindustry is beginning to view the Web as an operating system: e.g.,Google's Chrome OS and Firefox OS. This quick transformation has comeat a price. We are stuck with dynamic languages developed for theearly Web. These languages are unsuited to the development ofsophisticated web applications, resulting in modern applications beingeither overly conservative or needlessly unreliable and insecure.JavaScript is the most widely used language for client-side webprogramming: that is, in the web browser. Initially, JavaScript waswell-suited for the small web-programming tasks being asked ofit. With the modern Web however, the demands placed on JavaScript havebeen huge. The dynamic nature of JavaScript makes understanding itscode notoriously difficult, leading to buggy, untrusted code. Thisproject will provide a certifying verification tool for JavaScript toassert that e.g. a particular web application will maintain thestructure of a web page and not leak security information, or that abrowser extension will only perform permitted file systemoperations. Our tool will automatically generate proofs which will becertified (checked) by the well-known Coq proof assistant. Ourambitious aim is to ensure that the software we use to communicatewith our banks is at least as reliable as the software as our banksuse to communicate with each other.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Trustworthy Global Computing
值得信赖的全球计算
DOI:
10.1007/978-3-642-41157-1_7
发表时间:
2013
期刊:
影响因子:
--
作者:
[Bocchi L]
通讯作者:
Bocchi L
2016 Sepcial Track on Computer Security
2016 计算机安全专题
DOI:
--
发表时间:
2016
期刊:
影响因子:
--
作者:
[Bella G]
通讯作者:
Bella G
2015 Special Track on Computer Security
2015年计算机安全专题
DOI:
--
发表时间:
2015
期刊:
Proceedings of the ACM Symposium on Applied Computing
影响因子:
--
作者:
[Bella G.]
通讯作者:
Bella G.
JaVerT 2.0: compositional symbolic execution for JavaScript
JaVerT 2.0:JavaScript 的组合符号执行
DOI:
10.1145/3290379
发表时间:
2019
期刊:
Proceedings of the ACM on Programming Languages
影响因子:
--
作者:
[Fragoso Santos J]
通讯作者:
Fragoso Santos J
A trusted mechanised JavaScript specification
值得信赖的机械化 JavaScript 规范
DOI:
10.1145/2535838.2535876
发表时间:
2014
期刊:
影响因子:
--
作者:
[Bodin M]
通讯作者:
Bodin M
VeTSpec: Verified Trustworthy Software Specification
-
批准号:EP/R034567/1
-
项目类别:Fellowship
-
资助金额:$201.3万
-
财政年份:2018
-
负责人:Philippa Gardner
-
依托单位:
Research Institute in Verified Trustworthy Software Systems (VeTSS)
-
批准号:EP/P021921/1
-
项目类别:Research Grant
-
资助金额:$83.44万
-
财政年份:2017
-
负责人:Philippa Gardner
-
依托单位:
海外基金