Static checking of dynamically-varying security policies in database-backed applications

We present a system for sound static checking of security policies for database-backed Web applications. Our tool checks a combination of access control and information flow policies, where the policies vary based on database contents. For instance, one or more database tables may represent an acces...

Full description

Bibliographic Details
Main Author: Chlipala, Adam (Author)
Other Authors: Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science (Contributor)
Format: Article
Language:English
Published: USENIX Association, 2021-02-24T17:26:22Z.
Subjects:
Online Access:Get fulltext