Practical Cross-Tier Information Flow Control for Web Applications
dc.contributor.author | Liebe, Benjamin | |
dc.contributor.department | Chalmers tekniska högskola / Institutionen för data- och informationsteknik (Chalmers) | sv |
dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering (Chalmers) | en |
dc.date.accessioned | 2019-07-03T13:49:40Z | |
dc.date.available | 2019-07-03T13:49:40Z | |
dc.date.issued | 2015 | |
dc.description.abstract | Web applications are increasingly processing critical data. Maintaining information security in them is therefore a very important task. This is however a hard problem, as web applications typically split their functionality between different components in a three-tier architecture. One promising approach for this problem is to apply methods of Information Flow Control (IFC) across all tiers of web applications. These methods go beyond the possibilities of traditional security mechanisms such as access control and allow to tightly control where for example confidential information may or may not end up. Embedded into current research at Chalmers, this thesis aims to put the theory into practice: it first takes a closer look at what IFC actually means for web applications, which yields a discussion of how IFC policies can be used to better protect trust relationships and the business logic of the application. As a second step does the thesis use a given formal model for a security type system and turn it into a working prototype that extends the F# programming language in an unobtrusive way. Viability of this prototype is finally demonstrated by developing and discussing six different case studies that touch different aspects of web application development. The results show for the prototype that practical IFC requires a large initial effort but allows later a good integration into existing languages and development processes. | |
dc.identifier.uri | https://hdl.handle.net/20.500.12380/225248 | |
dc.language.iso | eng | |
dc.setspec.uppsok | Technology | |
dc.subject | Data- och informationsvetenskap | |
dc.subject | Computer and Information Science | |
dc.title | Practical Cross-Tier Information Flow Control for Web Applications | |
dc.type.degree | Examensarbete för masterexamen | sv |
dc.type.degree | Master Thesis | en |
dc.type.uppsok | H | |
local.programme | Computer systems and networks (MPCSN), MSc |
Ladda ner
Original bundle
1 - 1 av 1
Hämtar...
- Namn:
- 225248.pdf
- Storlek:
- 815.12 KB
- Format:
- Adobe Portable Document Format
- Beskrivning:
- Fulltext