-
23
pages
-
English
-
Documents
Description
Computer security Goal: prevent bad things from happeningPLDI’06 Tutorial T1: Clients not paying for services Critical service unavailableEnforcing and Expressing Security Confidential information leakedwith Programming Languages Important information damaged System used to violate laws (e.g., copyright)Andrew Myers Conventional security mechanisms aren’tup to the challengeCornell Universityhttp://www.cs.cornell.edu/andruPLDI Tutorial: Enforcing and Expressing Security with Programming Languages - Andrew Myers 2Harder & more important Language-based securityIn the ’70s, computing systems were isolated. Conventional security: program is black box software updates done infrequently by an experienced Encryptionadministrator. Firewalls you trusted the (few) programs you ran. System calls/privileged mode physical access was required. Process-level privilege and permissions-based access control crashes and outages didn’t cost billions. Prevents addressing important security issues:The Internet has changed all of this. Downloaded and mobile code we depend upon the infrastructure for everyday services Buffer overruns and other safety problems you have no idea what programs do. Extensible systems software is constantly updated – sometimes without your knowledgeor consent. Application-level security policies a hacker in the Philippines is as close as your neighbor. System-level security validation everything is ...
-
Publié par
-
Langue
English