|
TR-546-97
Extensible Security Architectures for Java |
|
| Authors: | Wallach, Dan S., Balfanz, Dirk, Dean, Drew, Felten, Edward W. |
| Date: | April 1997 |
| Pages: | 16 |
| Download Formats: | [Postscript] |
Mobile code technologies such as Java, JavaScript, and ActiveX generally limit all programs to a single security policy. However, software-based protection can allow for more flexible security models, with potentially significant performance improvements over traditional hardware-based solutions. We describe and analyze three implementation strategies for interposing flexible security policies in software-based security systems. Implementations exist for all three strategies: several vendors have adapted capabilities to Java, Netscape Communicator extended Java's stack introspection, and we built a type-hiding system as an add-on to Microsoft Internet Explorer. |
|