...
首页> 外文期刊>ACM SIGPLAN Notices: A Monthly Publication of the Special Interest Group on Programming Languages >Programming Languages and Program Analysis for Security A Three-Year Retrospective
【24h】

Programming Languages and Program Analysis for Security A Three-Year Retrospective

机译:三年回顾性安全性的编程语言和程序分析

获取原文
获取原文并翻译 | 示例

摘要

Software security has been traditionally enforced at the level of operating systems. However, operating systems have become increasingly large and complex, and it is very difficult-if not impossible-to enforce software security solely through them. Moreover, operating-system security allows dealing primarily with access-control policies on resources such as files and network connections. However, attacks may happen at both lower and higher levels of abstraction, and may target the internal behavior of applications, such as today's Web-based applications. Therefore, defenses must offer protection at the level of applications. Language-based security is the area of research that studies how to enforce application-level security using programming-language and program-analysis techniques. This area of research has become very active with the advent of Web applications. In 2006, the ACM SIGPLAN has introduced a new yearly forum entirely dedicated to the discussion of language-based-security research: Programming Languages and Analysis for Security (PLAS). This paper is a three-year survey of PLAS papers that discusses the progress made in the area of language-based security.
机译:传统上,软件安全性是在操作系统级别上实施的。但是,操作系统已经变得越来越大和复杂,并且仅通过它们来实施软件安全性就非常困难(即使不是不可能的话)。此外,操作系统安全性允许主要处理对文件和网络连接等资源的访问控制策略。但是,攻击可能同时发生在较低和较高的抽象级别上,并且可能针对应用程序(例如当今基于Web的应用程序)的内部行为。因此,防御必须在应用程序级别提供保护。基于语言的安全性是研究如何使用编程语言和程序分析技术强制执行应用程序级安全性的研究领域。随着Web应用程序的出现,这一领域的研究变得非常活跃。在2006年,ACM SIGPLAN引入了一个新的年度论坛,专门讨论基于语言的安全性研究:编程语言和安全性分析(PLAS)。本文是对PLAS论文的为期三年的调查,其中讨论了基于语言的安全领域中取得的进展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号