2019 · 14 citations · 40 references
EngineeringInformation SecurityCompiler TechnologyStatic Dataflow AnalysisCompiler-based SchemeFormal VerificationSoftware AnalysisHardware SecurityCompilersCompiler SupportComputer EngineeringComputer ScienceStatic Program AnalysisLanguage-based SecurityData SecurityCryptographySoftware SecurityRuntime InstrumentationProgram AnalysisSystem Software
We present a compiler-based scheme to protect the confidentiality of sensitive data in low-level applications (e.g. those written in C) in the presence of an active adversary. In our scheme, the programmer marks sensitive data by lightweight annotations on the top-level definitions in the source code. The compiler then uses a combination of static dataflow analysis, runtime instrumentation, and a novel taint-aware form of control-flow integrity to prevent data leaks even in the presence of low-level attacks. To reduce runtime overheads, the compiler uses a novel memory layout.
40
Nicholas Nethercote, Julian Seward · 2007 · 2.2K citations
Engineering, Computer Architecture, Software Engineering +18
A lattice model of secure information flow
Dorothy E. Denning · Communications of the ACM · 1976 · 1.9K citations · Full text
The geometry of innocent flesh on the bone
Hovav Shacham · 2007 · 1.3K citations