Wyvern: Impacting Software Security via Programming Language Design
Breaches of software security affect millions of people, and therefore it is crucial to strive for more secure software systems. However, the effect of programming language design on software security is not easily measured or studied. In the absence of scientific insight, opinions range from those that claim that programming language design has no effect on security of the system, to those that believe that programming language design is the only way to provide “high-assurance software.” In this paper, we discuss how programming language design can impact software security by looking at a specific example: the Wyvern programming language. We report on how the design of the Wyvern programming language leverages security principles, together with hypotheses about how usability impacts security, in order to prevent command injection attacks. Furthermore, we discuss what security principles we considered in Wyvern’s design.
(plateau2014_submission_6.pdf) | 77KiB |
Tue 21 OctDisplayed time zone: Tijuana, Baja California change
15:30 - 17:00 | |||
15:30 22mTalk | Wyvern: Impacting Software Security via Programming Language Design PLATEAU Darya Melicher Carnegie Mellon University, Alex Potanin Victoria University of Wellington, Jonathan Aldrich Carnegie Mellon University File Attached | ||
15:52 22mTalk | Considering Productivity Effects of Explicit Type Declarations PLATEAU Michael Coblenz Carnegie Mellon University, Jonathan Aldrich Carnegie Mellon University, Brad A. Myers Carnegie Mellon University, Joshua Sunshine Carnegie Mellon University File Attached | ||
16:15 22mTalk | Usability Hypotheses in the Design of Plaid PLATEAU File Attached | ||
16:37 22mOther | Group Activity PLATEAU |