STORM: Refinement Types for Secure Web Applications
Nico Lehmann, Rose Kunkel, Jordan Brown, Jean Yang, Niki Vazou, Nadia Polikarpova, Deian Stefan, Ranjit Jhala
摘要
We present Storm, a web framework that allows developers to build MVC applications with compile-time enforcement of centrally specified data-dependent security policies. Storm ensures security using a Security Typed ORM that refines the (type) abstractions of each layer of the MVC API with logical assertions that describe the data produced and consumed by the underlying operation and the users allowed access to that data. To evaluate the security guarantees of Storm, we build a formally verified reference implementation using the Labeled IO (LIO) IFC framework. We present case studies and end-to-end applications that show how Storm lets developers specify diverse policies while centralizing the trusted code to under 1% of the application, and statically enforces security with modest type annotation overhead, and no run-time cost.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Blockaid: Data Access Policy Enforcement for Web ApplicationsWen Zhang, Eric Sheng, Michael Alan Chang, Aurojit Panda 等OSDI 2022 · 被引用 8 次
- Mechanizing Refinement TypesMichael Borkowski, Niki Vazou, Ranjit JhalaPOPL 2024 · 被引用 7 次
- Usability Barriers for Liquid TypesCatarina Gamboa, Abigail Reese, Alcides Fonseca, Jonathan AldrichPLDI 2025 · 被引用 4 次
- REFTY: Refinement Types for Valid Deep Learning ModelsYanjie Gao, Zhengxian Li, Haoxiang Lin, Hongyu Zhang 等ICSE 2022 · 被引用 4 次
- Generic Refinement TypesNico Lehmann, Cole Kurashige, Nikhil Akiti, Niroop Krishnakumar 等POPL 2025 · 被引用 3 次
它引用的顶会 Paper4
- Build It, Break It, Fix It: Contesting Secure DevelopmentAndrew Ruef, Michael W. Hicks, James Parker, Dave Levin 等CCS 2016 · 被引用 80 次
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn 等NDSS 2018 · 被引用 66 次
- Verena: End-to-End Integrity Protection for Web ApplicationsNikolaos Karapanos, Alexandros Filios, Raluca Ada Popa, Srdjan CapkunS&P 2016 · 被引用 59 次
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg 等USENIX Security 2017 · 被引用 46 次
相关 Paper
- Scooter & Sidecar: a domain-specific approach to writing secure database migrationsJohn Renner, Alex Sanchez-Stern, Fraser Brown, Sorin Lerner 等PLDI 2021 · 被引用 1 次
- Verifiable Security Policies for Distributed SystemsFelix A. Wolf, Peter MüllerCCS 2024 · 被引用 1 次
- Securing Verified IO Programs Against Unverified Code in FCezar-Constantin Andrici, Stefan Ciobaca, Catalin Hritcu, Guido Martínez 等POPL 2024 · 被引用 5 次
- StarMalloc: Verifying a Modern, Hardened Memory AllocatorAntonin Reitz, Aymeric Fromherz, Jonathan ProtzenkoOOPSLA 2024 · 被引用 5 次
- Sesame: Practical End-to-End Privacy Compliance with Policy Containers and Privacy RegionsKinan Dak Albab, Artem Agvanian, Allen Aby, Corinn Tiffany 等SOSP 2024 · 被引用 2 次
