A framework for specifying and formally verifying application security policies
Name
1128823765-MIT.pdf
Size
369.39 KB
Format
Adobe PDF
Checksum (MD5)
495a06b879c5de4f7f3d51d7e637dd79
Author(s)
Shao, Christopher,M. Eng.Massachusetts Institute of Technology.
Advisor(s)
Adam Chlipala.
Date Issued
2019
Publisher
Massachusetts Institute of Technology
Abstract
One challenge of building software applications that handle sensitive information is ensuring that they meet certain security and privacy policies, which guide how the application should be written in order to satisfy particular security properties. Common examples of security policies include information-flow control and access control. In complex applications, which can be composed of many stateful components, it is hard to reason about all possible interactions and check that a policy is satisfied in every case. In this thesis, we present work on a new static-analysis framework in the Coq proof assistant to verify that implementations of applications meet their specified security policies, using proofs of indistinguishability of labeled transition systems. The primary goal of our framework is to be applicable to a wide variety of applications and policies, moreso than existing analysis tools. In addition to a formalization of applications and policies, we discuss some theorems to reduce manual proof effort and enable modular development. Finally, we apply our framework to some simple examples.
Description
This electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.
Thesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2019
Cataloged from student-submitted PDF version of thesis.
Includes bibliographical references (pages 59-60).
Subjects
Electrical Engineering and Computer Science.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission.
Persistent DSpace Link