2011 · 41 citations · 31 references
EngineeringInformation SecurityCompiler TechnologySoftware EngineeringSoftware AnalysisFormal VerificationNew RuntimeHardware SecurityCompilersDynamic CompilationSecurity RiskComputer EngineeringComputer ScienceOptimizing CompilerStatic Program AnalysisLanguage-based SecurityData SecurityManaged LanguageSoftware SecurityProgram AnalysisSoftware TestingFormal MethodsLanguage-independent SandboxingGarbage CollectionSystem Software
When dealing with dynamic, untrusted content, such as on the Web, software behavior must be sandboxed, typically through use of a language like JavaScript. However, even for such specially-designed languages, it is difficult to ensure the safety of highly-optimized, dynamic language runtimes which, for efficiency, rely on advanced techniques such as Just-In-Time (JIT) compilation, large libraries of native-code support routines, and intricate mechanisms for multi-threading and garbage collection. Each new runtime provides a new potential attack surface and this security risk raises a barrier to the adoption of new languages for creating untrusted content.
31
Chi-Keung Luk, Robert Cohn, Robert Muth et al. · 2005 · 2.3K citations
Engineering, Computer Architecture, Software Engineering +16
George C. Necula · 1997 · 1.8K citations
Efficient software-based fault isolation
Robert Wahbe, Steven Lucco, Thomas E. Anderson et al. · 1993 · 1.2K citations · Full text
Software Maintenance, Engineering, Computer Architecture +19