Title :
Challenges for Security Typed Web Scripting Languages Design
Author :
Hassan, Doaa ; El-Kassas, S. ; Ziedan, Ibrahim
Author_Institution :
Nat. Telecomm. Inst., Cairo
Abstract :
This paper focuses on the different challenges to design a security typed web scripting language. It uses the type system approach on a simple imperative language that captures a subset of the security typed Web language constructs to express the security properties that must be held in the language with respect to its formal semantics to prevent insecure information flow in Web application system and hence the common Web application security vulnerabilities.
Keywords :
Web design; authoring languages; programming language semantics; security of data; type theory; formal semantics; imperative language; security typed Web scripting language design; type system approach; Access control; Automatic control; Control systems; Data security; Databases; Information security; Lattices; National security; Permission; Web server; Information flow security; type system; web application vulnerabilities; web scripting language;
Conference_Titel :
Information Assurance and Security, 2008. ISIAS '08. Fourth International Conference on
Conference_Location :
Naples
Print_ISBN :
978-0-7695-3324-7
DOI :
10.1109/IAS.2008.33