ACM Home Page
Please provide us with feedback. Feedback
Programming languages and program analysis for security: a three-year retrospective
Full text PdfPdf (206 KB)
Source
ACM SIGPLAN Notices archive
Volume 43 ,  Issue 12  (December 2008) table of contents
COLUMN: PLAS 2008 table of contents
Pages 32-39  
Year of Publication: 2009
ISSN:0362-1340
Authors
Marco Pistoia  IBM T. J. Watson Research Center
Úlfar Erlingsson  Reykjavík University
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 44,   Downloads (12 Months): 324,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1513443.1513449
What is a DOI?

ABSTRACT

Software security has been traditionally enforced at the level of operating systems. However, operating systems have become increasingly large and complex, and it is very difficult--if not impossible--to enforce software security solely through them. Moreover, operating-system security allows dealing primarily with access-control policies on resources such as files and network connections. However, attacks may happen at both lower and higher levels of abstraction, and may target the internal behavior of applications, such as today's Web-based applications. Therefore, defenses must offer protection at the level of applications. Language-based security is the area of research that studies how to enforce application-level security using programming-language and program-analysis techniques. This area of research has become very active with the advent of Web applications. In 2006, the ACM SIGPLAN has introduced a new yearly forum entirely dedicated to the discussion of language-based-security research: Programming Languages and Analysis for Security (PLAS). This paper is a three-year survey of PLAS papers that discusses the progress made in the area of language-based security.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
2
3
4
5
6
7
 
8
Eclipse Project, http://www.eclipse.org.
 
9
10
11
12
 
13
 
14
 
15
Joseph A. Goguen and José Meseguer. Security Policies and Security Models. In 1982 IEEE Symposium on Security and Privacy, pages 11--20, Oakland, CA, USA, May 1982. IEEE Computer Society Press.
 
16
17
18
19
20
21
22
23
24
25
 
26
 
27
28
29
30
31
 
32
33
34
 
35
Open Web Application Security Project (OWASP), http://www.owasp.org.
 
36
 
37
 
38
 
39
 
40
 
41
Jerome H. Saltzer and Michael D. Schroeder. The Protection of Information in Computer Systems. Proceedings of the IEEE, 63(9):1278--1308, September 1975.
42
43
44
45
 
46
47
48
 
49
50
51
 
52
53

Collaborative Colleagues:
Marco Pistoia: colleagues
Úlfar Erlingsson: colleagues