2007.09.12 |
| Date | Tue Sep 25 |
| Time | 11:15 — 12:00 |
| Location | DI-Turing-014 |
Title: Policy-Informed Program Analyses
Abstract:
Access-control policies play a central role in controlling the
dissemination of sensitive data in domains ranging from library
services to healthcare. They representan important but not isolated
example of policies or rules that govern the behavior of programs.
Developers increasingly extract these policies into separate modules
in their programs, expressing the policies in domain-specific,
declarative policy languages.
The subtle nature of thesepolicies suggests this is a natural domain
to apply formal methods, while the separation of the policy from the
rest of the program affords interesting opportunities. It is,
however, unclear that the straightforward application of verification
is appropriate or useful. We will discussthese issues, as well as
concrete results and tools we have produced.
The talk is self-contained, including a brief tutorial on
access-control.
Host: Olivier Danvy