Making Mobile Code Both Safe And Efficient

نویسندگان

  • Michael Franz
  • Wolfram Amme
  • Matthew Beers
  • Niall Dalton
  • Peter H. Fröhlich
  • Vivek Haldar
  • Andreas Hartmann
  • Peter S. Housel
  • Fermı́n Reig
  • Jeffery von Ronne
  • Christian H. Stork
  • Sergiy Zhenochin
چکیده

Mobile programs can potentially be malicious. To protect itself, a host that receives such mobile programs from an untrusted party or via an untrusted network connection will want some kind of guarantee that the mobile code is not about to cause any damage. The traditional solution to this problem has been verification, by which the receiving host examines the mobile program to discover all its actions even before starting execution. Unfortunately, aside from consuming computing resources in itself, verification inhibits traditional compiler optimizations, making such verifiable mobile code much less efficient than native code. We have found an alternative solution by identifying a class of mobile-code representations in which malicious programs can simply not be encoded to begin with. In such an encoding, verification turns into an integral part of the decoding routine. Moreover, support for high-quality justin-time code generation can be provided. We present two such encodings, one based on highly effective compression of abstract syntax trees, and another based on a referencesafe and type-safe variant of Static Single Assignment form. Parts of this material were previously published under the title “Project transPROse: Reconciling Mobile-Code Security With Execution Efficiency” in The Second DARPA Information Survivability Conference and Exhibition (DISCEX II), Anaheim, California, June 2001, IEEE Computer Society Press, ISBN 0-7695-1212-7, pp. II.196–II.210. This research effort was sponsored by the Defense Advanced Research Projects Agency (DARPA) and Air Force Research Laboratory (AFRL), Air Force Materiel Command, USAF, under agreement number F30602-99-1-0536. The U.S. Government is authorized to reproduce and distribute reprints for Governmental purposes notwithstanding any copyright annotation thereon. The views and conclusions contained herein are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of DARPA, AFRL, or the U.S. Government.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A green, efficient, and rapid procedure for the synthesis of pyrano[3,2-c] quinoline and pyrano[3,2-c]pyridone derivatives catalyzed by [BMIm]Cl

A highly practical and efficient preparation of pyrano[3,2-c]pyridone and pyrano[3,2-c]quinoline derivatives was developed via an ionic liquid mediated and promoted multi-component reaction of malononitrile, aldehyde, and 4-hydroxyquinolin-2(1H)-one or 4-hydroxy-6-methylpyridin-2(1H)-one. The combinatorial syntheses were achieved for the first time without applying extra activation energy at am...

متن کامل

A green, efficient, and rapid procedure for the synthesis of pyrano[3,2-c] quinoline and pyrano[3,2-c]pyridone derivatives catalyzed by [BMIm]Cl

A highly practical and efficient preparation of pyrano[3,2-c]pyridone and pyrano[3,2-c]quinoline derivatives was developed via an ionic liquid mediated and promoted multi-component reaction of malononitrile, aldehyde, and 4-hydroxyquinolin-2(1H)-one or 4-hydroxy-6-methylpyridin-2(1H)-one. The combinatorial syntheses were achieved for the first time without applying extra activation energy at am...

متن کامل

Secure Prolog Based Mobile Code

LogicWeb mobile code consists of Prolog-like rules embedded in Web pages, thereby adding logic programming behaviour to those pages. Since LogicWeb programs are downloaded from foreign hosts and executed locally, there is a need to protect the client from buggy or malicious code. A security model is crucial for making LogicWeb mobile code safe to execute. This paper presents such a model, which...

متن کامل

ارائه یک رویکرد همانند سازی شده عامل محور در اجرای یک الگوی کد متحرک مطمئن

Abstract Using mobile agents, it is possible to bring the code close to the resources, which is not foreseen by the traditional client/server paradigm. Compared to the client/server computing paradigm, the greater flexibility of the mobile agent paradigm comes at additional costs as well as the additional complexity of developing and managing mobile agent-based applications. Such complexity ...

متن کامل

The Security - Communication tradeoff in Mobile Computing

Mobile computing introduces a paradigm that enables new services to be deployed efficiently over the network. However, these new promising capabilities come with inherent security hazards, both for the machines that host the mobile code, and to the mobile code itself. In this paper we present a framework for the rigorous study of the latter problem, i.e., the ability of the mobile applet to car...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2003