e-ISSN: Pending
Failed Experiment ReportOpen accessComputer Science

When Good Components Go Bad: Formally Secure Compilation Despite Dynamic Compromise

Carmine Abate; Arthur Azevedo de Amorim; Roberto Blanco; Ana Nora Evans; Guglielmo Fachini; Catalin Hritcu; Théo Laurent; Benjamin C. Pierce · 2018 · arXiv

WASTE classifies this as Failed Experiment Report · AI classification, approximate

An experimental approach did not work as intended — learn what to avoid before investing the same effort.

Abstract (excerpt)

We propose a new formal criterion for evaluating secure compilation schemes for unsafe languages, expressing end-to-end security guarantees for software components that may become compromised after encountering undefined behavior---for example, by accessing an array out of bounds. Our criterion is the first to model dynamic compromise in a system of mutually distrustful components with clearly specified privileges. It articulates how each component should be protected from all the others---in particular, from components that have encountered undefined behavior and become compromised. Each comp

Excerpt shown for reference under fair use — read the full paper at the publisher.

About to run something similar?

Run an AI Precheck on your own design to catch failure modes like this one before you spend the time. Your first desk check is free.

WASTE indexes this work — it does not host or republish it. Failure-type classification is automated and approximate.

Metadata source: arXiv