This work sounds like, in 5 years, after they're finished understanding the last 30 years of parser research, they'll discover the subsequent explosion of type system and model checking research, and move on to that for whitelisting.
Extra oddity: language-based security is an entire field.
Edit: I'm happy that they're advocating the application of these techniques, and especially helping implementors pin-point where it's needed, I'm just confused at their selection of techniques.
it's especially confusing since model checking and verification research has been lively for the past twenty years and recently produced some pretty good results (like bedrock and ironclad), but this is all willfully ignored by the langsec community...
Comments
This work sounds like, in 5 years, after they're finished understanding the last 30 years of parser research, they'll discover the subsequent explosion of type system and model checking research, and move on to that for whitelisting.
Extra oddity: language-based security is an entire field.
Edit: I'm happy that they're advocating the application of these techniques, and especially helping implementors pin-point where it's needed, I'm just confused at their selection of techniques.
Langsec knows all about type theory:
See https://www.youtube.com/watch?v=3kEfedtQVOY&feature=youtu.be... (about 90 seconds)
n.b. that Merideth Patterson, the speaker in that video, is one of the original authors of langsec.
I think that clip supports my statement.
it's especially confusing since model checking and verification research has been lively for the past twenty years and recently produced some pretty good results (like bedrock and ironclad), but this is all willfully ignored by the langsec community...