Enforcing authorization policies using transactional memory introspection

25Citations
Citations of this article
46Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Correct enforcement of authorization policies is a difficult task, especially for multi-threaded software. Even in carefully-reviewed code, unauthorized access may be possible in subtle corner cases. We introduce Transactional Memory Introspection (TMI), a novel reference monitor architecture that builds on Software Transactional Memory a new, attractive alternative for writing correct, multi-threaded software. TMI facilitates correct security enforcement by simplifying how the reference monitor integrates with software functionality. TMI can ensure complete mediation of security-relevant operations, eliminate race conditions related to security checks, and simplify handling of authorization failures. We present the design and implementation of a TMI-based reference monitor and experiment with its use in enforcing authorization policies on four significant servers. Our experiments confirm the benefits of the TMI architecture and show that it imposes an acceptable runtime overhead. Copyright 2008 ACM.

Cite

CITATION STYLE

APA

Birgisson, A., Dhawan, M., Erlingsson, Ú., Ganapathy, V., & Iftode, L. (2008). Enforcing authorization policies using transactional memory introspection. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 223–234). https://doi.org/10.1145/1455770.1455800

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free