Seminar, 18th March 1997

[ Changed 20th March 1997 ]


Speaker:
Drew Dean, Princeton University
(joint work with Dirk Balfanz, Ed Felten, and Dan Wallach)

Date:
Tuesday 18th March

Place:
Room TP4, Computer Laboratory

Title:
THE IMPACT OF DYNAMIC LINKING ON JAVA SECURITY


We survey some of the major security flaws found in Java-enabled web browsers from Sun, Netscape, and Microsoft over the last 15 months. While numerous issues have been found throughout the system, the worst problems come from type safety failures in the implementations that allow an attacker to run arbitrary machine code. Several of the type safety failures can be traced to dynamic linking. We examine a formal model of dynamic linking, and find some necessary conditions for safety.


Seminar, 18th March 1997 / Mark.Lomas@cl.cam.ac.uk