Application Security Tools White Papers

Hardware Enforcement of Application Security Policies Using Tagged Memory

Overview Computers are notoriously insecure, in part because application security policies do not map well onto traditional protection mechanisms such as Unix user accounts or hardware page tables. This paper shows that enforcement of these policies can be pushed largely into the processor itself, by using tagged memory support, which can provide stronger security guarantees by enforcing application security even if the OS kernel is compromised. This paper presents the Loki tagged memory architecture, along with a novel operating system structure that takes advantage of tagged memory to enforce application security policies in hardware. The author has built a full-system prototype of Loki by modifying a synthesizable SPARC core, mapping it to an FPGA board, and porting HiStar, a Unix-like operating system, to run on it.

Further White Paper Details
PublisherStanford University File FormatPDF
Date PublishedOctober 2008
FormatWhite Papers   
Topics

Trial Download: Rational AppScan Standard Edition V7.9

To improve the security of web applications, it starts by building software securely. IBM Rational AppScan is a suite of Web application vulnerability scanners that include dynamic and static analysis...

Practical Approaches for Securing Web Applications across the Software Delivery Lifecycle

Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many don't understand, is how to implement a robust process for integrating security and...

Staying a step ahead of the hackers: the importance of identifying critical Web application vulnerabilities.

Security managers worldwide working for midsize or large organizations share a common goal: to better manage the risks associated with their business infrastructure. Web application security plays a significant role...

Webcast: Smart Techniques for application security: whitebox + blackbox testing.

Whitebox & blackbox application security testing are two approaches for detecting vulnerabilities in Web-based and network applications. Both have strengths and weaknesses, but a combination of the two provides the...

Is Your Security Effective? The Value of Application Security Testing Tools

Watch this new program and learn why you need strong application security testing tools, what these tools need to include, and where to turn to find the right solution for...


Quick Sitemap Links: