International Journal of Advances in Electronics and Computer Science ( IJAECS )
A highly rated peer reviewed monthly International Journal
Editor-in-Chief : Dr. P. Suresh
Contact Person : Technical Editor
Contact Mail : [email protected]  
Current Issue : Volume-11,Issue-2  ( Feb, 2024 ) View More
Journal Impact Factor : 2.68 View More

Journal Info
Publisher:IRAJ
ISSN (p): 2394-2835
Issues /Year :12
Stay up-to-date
Register your interests and receive email alerts tailored to your needs
Follow us
facebook twitter linked in

Paper Detail


Paper Title
Computerized Isolation and Little Privilege in Net Assistances

Abstract
In many client-facing applications, a vulnerability in any part can compromise the entire application. This paper describes the design and implementation of Passes, a system that protects a data store from unintended data leaks and unauthorized writes even in the face of application compromise. Passes automatically splits applications into sandboxed processes. Passes limits communication between those components and the types of accesses each component can make to shared storage, such as a backend database. In order to limit components to their little privilege, Passes uses dynamic analysis on developer-supplied end-to-end test cases to learn data and control-flow relationships between database queries and previous query results, and it then strongly enforces those relationships.Our prototype of Passes acts as a drop in replacement for the net framework. By running eleven unmodified, off-the-shelf applications in Passes, we demonstrate its ability to provide strong security guarantees—Passes correctly enforced 96% of the applications’ policies—with little additional overhead. Addtionally, in the net-specific setting of the prototype, we also mitigate the crosscomponent effects of cross-site scripting (XSS) attacks by combining browser HTML5 sandboxing techniques with our automatic component separation. Keywords- security policy inference; isolation; capabilities; principle of little privilege; net security


Author - P.Subba Rao, Sk.John Sydulu, Ch.Jyosthna Devi, M Markendeyulu

Published : Volume-4,Issue-4  ( Apr, 2017 )


DOIONLINE Number - IJAECS-IRAJ-DOIONLINE-7711   View Here

| PDF |
Viewed - 52
| Published on 2017-06-23
   
   
PAST ISSUES
Volume-11,Issue-1  ( Jan, 2024 )
Volume-10,Issue-12  ( Dec, 2023 )
Volume-10,Issue-11  ( Nov, 2023 )
Volume-10,Issue-10  ( Oct, 2023 )
Volume-10,Issue-9  ( Sep, 2023 )
Volume-10,Issue-8  ( Aug, 2023 )
Volume-10,Issue-7  ( Jul, 2023 )
Volume-10,Issue-6  ( Jun, 2023 )
Volume-10,Issue-5  ( May, 2023 )
Volume-10,Issue-4  ( Apr, 2023 )
Journal Indexed