|COOKIES: By using this website you agree that we can place Google Analytics Cookies on your device for performance monitoring.|
Aura: A Programming Language with Authorization and Audit
If you have a question about this talk, please contact Mateja Jamnik.
Existing mechanisms for authorizing and auditing the flow of information in networked computer systems are insufficient to meet the security requirements of high-assurance software systems. Current best practices typically rely on operating-system provided file permissions for authorization and an ad-hoc combination of OS and network-level (e.g. firewall-level) logging to generate audit trails.
This talk will describe work on a security-oriented programming language called Aura that attempts to address this problem of auditable information flows in a more principled way. Aura supports a built-in notion of principal and its type system incorporates ideas from authorization logic and information-flow constraints. These features, together with the Aura run-time system, enforce strong information-flow policies while generating good audit trails. These audit trails record access-control decisions (such as uses of downgrading or declassification) that influence how information flows through the system. Aura’s programming model is intended to smoothly integrate information-flow and access control constraints with the cryptographic enforcement mechanisms necessary in a distributed computing environment.
This is joint work with Jeff Vaughan, Limin Jia, Karl Mazurak, Jianzhou Zhou, Joseph Schorr, and Luke Zarko.
This talk is part of the Computer Laboratory Wednesday Seminars series.
This talk is included in these lists:
Note that ex-directory lists are not shown.
Other listsEurocrisis Conference 14-15 June Centre for Smart Infrastructure & Construction Cardiovascular Epidemiology Unit Special Seminars
Other talksA Visit with Poet Dmitry Vodennikov Functional genomics for schistosomes: approaches to interrogate host-parasite interaction, and schistosomiasis-associated diseases. ‘No longer the dismal science: the contribution of health economics to health gains in the developing world’ by Professor Dame Anne Mills Trinity College Science Society Annual Symposium Metrisability of Painleve equations, and Hamiltonian systems of hydrodynamic type Email