pith. sign in

arxiv: 0803.3230 · v2 · submitted 2008-03-21 · 💻 cs.CR · cs.OS· cs.PL

A Type System for Data-Flow Integrity on Windows Vista

classification 💻 cs.CR cs.OScs.PL
keywords vistawindowscodeintegritymodelsystemtrusteddata-flow
0
0 comments X
read the original abstract

The Windows Vista operating system implements an interesting model of multi-level integrity. We observe that in this model, trusted code can be blamed for any information-flow attack; thus, it is possible to eliminate such attacks by static analysis of trusted code. We formalize this model by designing a type system that can efficiently enforce data-flow integrity on Windows Vista. Typechecking guarantees that objects whose contents are statically trusted never contain untrusted values, regardless of what untrusted code runs in the environment. Some of Windows Vista's runtime access checks are necessary for soundness; others are redundant and can be optimized away.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.