Principled and Practical Web Application Security
, Stanford University
Date: Thursday, April 09, 2015
Time: 4:00 PM to 5:00 PM Note: all times are in the Eastern Time Zone
Refreshments: 3:45 PM
Host: Arvind, MIT
Contact: Joanne Talbot Hanley, 617-253-6054, email@example.com
Speaker URL: None
TALK: CS Special Seminar: Deian Stefan " Principled and Practical Web Application Security"
Abstract: Large-scale private user data theft has become a common occurrence on the web. A huge factor in these privacy breaches we hear so much
about is that developers specify and enforce data security policies by strewing checks throughout their application code. Overlooking even a
single check can lead to vulnerabilities.
In this talk, I will describe a new approach to protecting sensitive data even when application code is buggy or malicious. The key ideas
behind my approach are to separate the security and privacy concerns of an application from its functionality, and to use language-level
information flow control (IFC) to enforce policies throughout the code. The main challenge of this approach is at once to design
practical systems that can be easily adopted by average developers, and simultaneously to leverage formal semantics that rule out large
classes of design error. The talk will cover a server-side web framework (Hails), a language-level IFC system (LIO), and a browser
security architecture (COWL), which, together, provide end-to-end security against the privacy leaks that plague today's web applications.
Bio: Deian Stefan is a PhD student in Computer Science at Stanford. His research interests intersect systems, programming languages, and
security. As part of his PhD work, Deian focused on web application security; he built practical systems with formal underpinnings that enable average developers to build secure web applications. Deian is a recipient of a NDSEG Fellowship and a Mozilla Research Grant for his
work on web security. He is a co-founder and the CTO of GitStar Inc., a company that provides security-as-a-service to web developers. He
is a member of the W3C Web Application Security Group, where he serves as editor of the COWL spec. He received his BE and ME in Electrical
Engineering from Cooper Union.
To see all seminars in this series, go to: https://calendar.csail.mit.edu/seminar_series/7949
Created by Joanne Talbot Hanley at Monday, February 23, 2015 at 4:41 PM.