课题基金 / 基金详情

Collaborative Research: Integrating Pointer Confinement and Access Control for Encapsulation

Collaborative Research: Integrating Pointer Confinement and Access Control for Encapsulation
协作研究:集成指针限制和访问控制进行封装
批准号:
0208984
负责人:
David Naumann
金额:
$16.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-09-01 至 2006-08-31

项目摘要

项目成果

David Naumann的其他基金

相似基金

相关文献

中文摘要
翻译
在现代计算机系统中,计算分布在许多主机上。互不信任的机器和用户共存,软件是使用从远程主机下载的即插即用组件构建的。多个用户共享资源,因此确保(例如,私人信息)不被泄露至关重要。像Java和c#这样的语言被设计成通过强制封装边界来限制程序组件之间的相互依赖和信息流来提供这样的安全性。然而,这种边界被无处不在的指针混叠破坏,这可能被恶意利用来泄露敏感信息。本项目研究将指针限制在其预期作用域的方法。重点是静态分析和动态访问控制之间的相互作用,以实现限制。技术目标是找到可用于确保使用动态绑定、多线程、继承、基于类的封装和访问控制实现的系统中的安全信息流的约束机制。还研究了最小化限制和访问控制的运行时性能成本的分析和转换。这项工作将带来更好的编程方法和工具,用于开发基于web的服务和其他需要高水平保证的分布式应用程序。这项工作将有助于实现编程语言和检查应用程序中的安全缺陷的技术。
英文摘要
In modern computer systems, computation is distributed over many host machines. Mutually untrusted machines and users coexist, and software is built using plug-and-play components downloaded from remote hosts. Multiple users share resources so it is critical to ensure, e.g., that private information is not compromised. Languages like Java and C# are designed to provide such security by enforcing encapsulation boundaries that restrict interdependencies and information flows between program components. Such boundaries are undercut, however, by ubiquitous pointer aliasing which can be maliciously exploited to leak sensitive information.This project studies ways to confine pointers to their intended scopes. The focus is on the interplay between static analysis and dynamic access control to achieve confinement. The technical goal is to find confinement regimes that can be used to assure secure information flow in systems implemented using dynamic binding, multithreading, inheritance, class-based encapsulation, and access control. Analyses and transformations to minimize run-time performance costs for confinement and access control are also investigated. This work will lead to better programming methods and tools for development of web-based services and other distributed applications that require a high level of assurance. The work will contribute to technology for implementing programming languages and for checking for security flaws in application programs.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Relational Verification for Information Assurance and Privacy
  • 批准号:
    1718713
  • 项目类别:
    Standard Grant
  • 资助金额:
    $45.19万
  • 财政年份:
    2017
  • 负责人:
    David Naumann
  • 依托单位:
EAGER: Hyperproperty Abstraction for Information Flow Control
  • 批准号:
    1649894
  • 项目类别:
    Standard Grant
  • 资助金额:
    $10.48万
  • 财政年份:
    2016
  • 负责人:
    David Naumann
  • 依托单位:
TWC: Medium: Collaborative: Flexible and Practical Information Flow Assurance for Mobile Apps
  • 批准号:
    1228930
  • 项目类别:
    Standard Grant
  • 资助金额:
    $52.66万
  • 财政年份:
    2012
  • 负责人:
    David Naumann
  • 依托单位:
SHF: Small: Collaborative Research: Specification Language Foundations for Modular Reasoning Methodologies
  • 批准号:
    0915611
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.99万
  • 财政年份:
    2009
  • 负责人:
    David Naumann
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)