Back to results

Massachusetts Institute of Technology

A framework for specifying and formally verifying application security policies

Abstract

dc:description.abstract

One challenge of building software applications that handle sensitive information is ensuring that they meet certain security and privacy policies, which guide how the application should be written in order to satisfy particular security properties. Common examples of security policies include information-flow control and access control. In complex applications, which can be composed of many stateful components, it is hard to reason about all possible interactions and check that a policy is satisfied in every case. In this thesis, we present work on a new static-analysis framework in the Coq proof assistant to verify that implementations of applications meet their specified security policies, using proofs of indistinguishability of labeled transition systems. The primary goal of our framework is to be applicable to a wide variety of applications and policies, moreso than existing analysis tools. In addition to a formalization of applications and policies, we discuss some theorems to reduce manual proof effort and enable modular development. Finally, we apply our framework to some simple examples.

Degree

thesis:*
Name thesis:degree_name
Master
Department dc:contributor.department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Grantor dc:publisher
Massachusetts Institute of Technology
Year dc:date.issued
2019

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Shao, Christopher,M. Eng.Massachusetts Institute of Technology.
Advisor dc:contributor.advisor
  • Adam Chlipala.

Subjects

dc:subject × 1

Rights

dc:rights
Statement dc:rights
  • MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission.
Language dc:language.iso
eng

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/1721.1/123144
OAI identifier oai:identifier
oai:dspace.mit.edu:1721.1/123144

Chain of custody

source
Harvested from
MIT
Base URL
dspace.mit.edu/oai/request
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Shao, Christopher,M. Eng.Massachusetts Institute of Technology.. A framework for specifying and formally verifying application security policies. Massachusetts Institute of Technology, 2019. https://hdl.handle.net/1721.1/123144