Computing technology has made recording and copying information cheap and convenient, resulting in numerous security problems: from accidental copying leading to confidentiality breaches to rapid proliferation of spam, worms and other malicious code. At the same time, distributed information systems provide value through efficient information dissemination. This thesis investigates techniques that address the challenge of building distributed systems while providing the assurance of security. This thesis first focuses on web information systems based on the clientserver communication paradigm. Servlet Information Flow (SIF) is a novel software framework for building high-assurance web applications. Security concerns are expressed as end-to-...
This paper studies the foundations of information-flow security for interactive programs. Previous r...
This thesis proposes a typing discipline to control the migration of code in a distributed, mobile e...
Abstract — Application-level web security refers to obligation inherent in the code of a web-applica...
SIF (Servlet Information Flow) is a novel software framework for building high-assurance web applica...
Private and confidential information is increasingly stored online and increasingly being exposed du...
The Web is evolving into a melting pot of content coming from multiple stakeholders. In this mutuall...
As more and more sensitive data is handled by software, itstrustworthiness becomes an increasingly i...
We are entering an era in which federated information systems are widely used to share information a...
© Springer International Publishing Switzerland 2014. Modern web applications heavily rely on JavaSc...
Information-flow control is an important element in computer system security, and there has been sig...
Web applications are now critical infrastructure. To improve the user interface, some application f...
Web applications are now critical infrastructure. To improve the user interface, some application fu...
A large extent of today's computer programs is distributed. For instance, services for backups, fil...
Web applications are often vulnerable to code injection attacks and to attacksthrough buggy or malic...
There is an increasing prevalence of Web software that collects end-user information and transmits i...
This paper studies the foundations of information-flow security for interactive programs. Previous r...
This thesis proposes a typing discipline to control the migration of code in a distributed, mobile e...
Abstract — Application-level web security refers to obligation inherent in the code of a web-applica...
SIF (Servlet Information Flow) is a novel software framework for building high-assurance web applica...
Private and confidential information is increasingly stored online and increasingly being exposed du...
The Web is evolving into a melting pot of content coming from multiple stakeholders. In this mutuall...
As more and more sensitive data is handled by software, itstrustworthiness becomes an increasingly i...
We are entering an era in which federated information systems are widely used to share information a...
© Springer International Publishing Switzerland 2014. Modern web applications heavily rely on JavaSc...
Information-flow control is an important element in computer system security, and there has been sig...
Web applications are now critical infrastructure. To improve the user interface, some application f...
Web applications are now critical infrastructure. To improve the user interface, some application fu...
A large extent of today's computer programs is distributed. For instance, services for backups, fil...
Web applications are often vulnerable to code injection attacks and to attacksthrough buggy or malic...
There is an increasing prevalence of Web software that collects end-user information and transmits i...
This paper studies the foundations of information-flow security for interactive programs. Previous r...
This thesis proposes a typing discipline to control the migration of code in a distributed, mobile e...
Abstract — Application-level web security refers to obligation inherent in the code of a web-applica...