Making information flow explicit in HiStar
Name
Zeldovich_Making information.pdf
Size
228.35 KB
Format
Adobe PDF
Checksum (MD5)
a25c33232bfce530c87fdaebcfd4d1af
Author(s) • • •
Zeldovich, Nickolai
Boyd-Wickizer, Silas
Kohler, Eddie
Mazieres, David
Date Issued
November 2011
Journal
Communications of the ACM
Publisher
Association for Computing Machinery (ACM)
Citation
Nickolai Zeldovich, Silas Boyd-Wickizer, Eddie Kohler, and David Mazières. 2011. Making information flow explicit in HiStar. Commun. ACM 54, 11 (November 2011), 93-101.
Version
Author's final manuscript
Abstract
HiStar is a new operating system designed to minimize the amount of code that must be trusted. HiStar provides strict information flow control, which allows users to specify precise data security policies without unduly limiting the structure of applications. HiStar's security features make it possible to implement a Unix-like environment with acceptable performance almost entirely in an untrusted user-level library. The system has no notion of superuser and no fully trusted code other than the kernel. HiStar's features permit several novel applications, including privacy-preserving, untrusted virus scanners and a dynamic Web server with only a few thousand lines of trusted code.
MIT Department
Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike 3.0
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1145/2018396.2018419