  1. 1. Lightweight Enforcement of Fine-Grained Security Policies for Untrusted Software

    Författare :Phu Phung; Chalmers University of Technology; []
    Nyckelord :NATURVETENSKAP; NATURAL SCIENCES; security policy enforcement; JavaScript security; web-application security; vehicle software security; untrusted software;

    Sammanfattning : This thesis presents an innovative approach to implementing a security enforcement mechanism in the contexts of untrusted software systems, where a piece of code in a base system may come from an untrusted third party. The key point of the approach is that it is lightweight in the sense that it does not need an additional policy language or extra tool.

  2. 2. Lightweight Inlined Reference Monitors for Securing Extensible and Open Systems

    Författare :Phu Phung; Chalmers University of Technology; []
    Nyckelord :NATURVETENSKAP; NATURAL SCIENCES; Security; Inlined Reference Monitors; JavaScript; Vehicle Software Security;

    Sammanfattning : This thesis studies an alternative implementation of asecurity reference monitor in the contexts of extensible and opensystems. A security reference monitor is a classic approach to imposing asecurity policy on an otherwise untrusted system by using a trusted componentwhich intercepts security-relevant resource requests and applies a securitypolicy to decide whether to grant such requests.

  3. 3. Tracking Dependencies for Security and Privacy

    Författare :Arnar Birgisson; Chalmers University of Technology; []
    Nyckelord :NATURVETENSKAP; NATURAL SCIENCES; Programming Languages; Software Security; Web Security;

    Sammanfattning : Information Flow Control is a well established field of research, providing asuite of theoretical and practical results. However, adoption to real worldsystems has yet to catch up. This thesis seeks to expand the boundaries ofthis field, in particular with the aim of making Information Flow Control moreapplicable to real world scenarios.

  4. 4. Information Flow for Web Security and Privacy

    Författare :Alexander Sjösten; Chalmers University of Technology; []
    Nyckelord :NATURVETENSKAP; NATURAL SCIENCES; filter list generation; web security; browser extensions; information-flow control; browser fingerprinting; side-effectful libraries;

    Sammanfattning : The use of libraries is prevalent in modern web development. But how to ensure sensitive data is not being leaked through these libraries? This is the first challenge this thesis aims to solve.

  5. 5. Information-Flow Tracking for Web Security

    Författare :Luciano Bello; Chalmers University of Technology; []

    Sammanfattning : The Web is evolving into a melting pot of content coming from multiple stakeholders. In this mutually distrustful setting, the combination of code and data from different providers demands new security approaches.This thesis explores information-flow control technologies to provide security for the current Web.