STORM: Refinement Types for Secure Web Applications
Nico Lehmann, Rose Kunkel, Jordan Brown, Jean Yang, Niki Vazou, Nadia Polikarpova, Deian Stefan, Ranjit Jhala
Abstract
We present Storm, a web framework that allows developers to build MVC applications with compile-time enforcement of centrally specified data-dependent security policies. Storm ensures security using a Security Typed ORM that refines the (type) abstractions of each layer of the MVC API with logical assertions that describe the data produced and consumed by the underlying operation and the users allowed access to that data. To evaluate the security guarantees of Storm, we build a formally verified reference implementation using the Labeled IO (LIO) IFC framework. We present case studies and end-to-end applications that show how Storm lets developers specify diverse policies while centralizing the trusted code to under 1% of the application, and statically enforces security with modest type annotation overhead, and no run-time cost.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- Blockaid: Data Access Policy Enforcement for Web ApplicationsWen Zhang, Eric Sheng, Michael Alan Chang, Aurojit Panda et al.OSDI 2022 · 8 citations
- Mechanizing Refinement TypesMichael Borkowski, Niki Vazou, Ranjit JhalaPOPL 2024 · 7 citations
- Usability Barriers for Liquid TypesCatarina Gamboa, Abigail Reese, Alcides Fonseca, Jonathan AldrichPLDI 2025 · 4 citations
- REFTY: Refinement Types for Valid Deep Learning ModelsYanjie Gao, Zhengxian Li, Haoxiang Lin, Hongyu Zhang et al.ICSE 2022 · 4 citations
- Generic Refinement TypesNico Lehmann, Cole Kurashige, Nikhil Akiti, Niroop Krishnakumar et al.POPL 2025 · 3 citations
Builds on4
- Build It, Break It, Fix It: Contesting Secure DevelopmentAndrew Ruef, Michael W. Hicks, James Parker, Dave Levin et al.CCS 2016 · 80 citations
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn et al.NDSS 2018 · 66 citations
- Verena: End-to-End Integrity Protection for Web ApplicationsNikolaos Karapanos, Alexandros Filios, Raluca Ada Popa, Srdjan CapkunS&P 2016 · 59 citations
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg et al.USENIX Security 2017 · 46 citations
Related papers
- Scooter & Sidecar: a domain-specific approach to writing secure database migrationsJohn Renner, Alex Sanchez-Stern, Fraser Brown, Sorin Lerner et al.PLDI 2021 · 1 citation
- Verifiable Security Policies for Distributed SystemsFelix A. Wolf, Peter MüllerCCS 2024 · 1 citation
- Securing Verified IO Programs Against Unverified Code in FCezar-Constantin Andrici, Stefan Ciobaca, Catalin Hritcu, Guido Martínez et al.POPL 2024 · 5 citations
- StarMalloc: Verifying a Modern, Hardened Memory AllocatorAntonin Reitz, Aymeric Fromherz, Jonathan ProtzenkoOOPSLA 2024 · 5 citations
- Sesame: Practical End-to-End Privacy Compliance with Policy Containers and Privacy RegionsKinan Dak Albab, Artem Agvanian, Allen Aby, Corinn Tiffany et al.SOSP 2024 · 2 citations
