Clean Application Compartmentalization with SOAAP
- đ¤ Speaker: Khilan Gudka (University of Cambridge)
- đ Date & Time: Thursday 01 October 2015, 15:00 - 16:00
- đ Venue: FW26, Computer Laboratory, William Gates Building
Abstract
Application compartmentalization, a vulnerability mitigation technique employed in programs such as OpenSSH and the Chromium web browser, decomposes software into isolated components to limit privileges leaked or otherwise available to attackers. However, compartmentalizing applications â and maintaining that compartmentalization â is hindered by ad hoc methodologies and significantly increased programming effort. In practice, programmers stumble through (rather than overtly reason about) compartmentalization spaces of possible decompositions, unknowingly trading off correctness, security, complexity, and performance. We present a new conceptual framework embodied in an LLVM -based tool: the Security-Oriented Analysis of Application Programs (SOAAP) that allows programmers to reason about compartmentalization using source-code annotations (compartmentalization hypotheses). We demonstrate considerable benefit when creating new compartmentalizations for complex applications, and analyze existing compartmentalized applications to discover design faults and maintenance issues arising from application evolution.
Bio: Khilan Gudka is a Research Associate in the Security group at the University of Cambridge Computer Laboratory. Prior to this he did his PhD at Imperial College London. His research interests include software compartmentalisation, capability systems, static/dynamic program analysis, compilers/runtimes and concurrency.
Series This talk is part of the Computer Laboratory Systems Research Group Seminar series.
Included in Lists
- All Talks (aka the CURE list)
- bld31
- Cambridge Centre for Data-Driven Discovery (C2D3)
- Cambridge talks
- Chris Davis' list
- CL's SRG seminar
- Computer Laboratory Systems Research Group Seminar
- Department of Computer Science and Technology talks and seminars
- FW26, Computer Laboratory, William Gates Building
- Interested Talks
- ndk22's list
- ob366-ai4er
- rp587
- School of Technology
- Trust & Technology Initiative - interesting events
- yk449
Note: Ex-directory lists are not shown.
![[Talks.cam]](/static/images/talkslogosmall.gif)

Khilan Gudka (University of Cambridge)
Thursday 01 October 2015, 15:00-16:00