Securing Java with Local Policies.

Massimo Bartoletti, Gabriele Costa, Pierpaolo Degano, Fabio Martinelli, Roberto Zunino · The Journal of Object Technology · 2009

We propose an extension to the security model of Java, that allows for specifying, analysing and enforcing history-based usage policies.Policies are defined by usage automata, that recognize the forbidden execution histories.Programmers can sandbox an untrusted piece of code with a policy, which is enforced at run-time through its local scope.A static analysis allows for optimizing the execution monitor: only the policies not guaranteed to be always obeyed will be enforced at run-time.

Read the paper · More papers on PaperTik