A Machine-Checked Safety Proof for a CISC-Compatible SFI Technique

Executing untrusted code while preserving security requires that thecode be prevented from modifying memory or executing instructionsexcept as explicitly allowed. Software-based fault isolation (SFI) or"sandboxing" enforces such a policy by rewriting code at theinstruction level. In prev...

Full description

Bibliographic Details
Main Author: McCamant, Stephen
Other Authors: Michael Ernst
Language:en_US
Published: 2006
Online Access:http://hdl.handle.net/1721.1/32546