NaCl to give way to RockSalt: tool to improve software fault isolation

21 Jul 2012

1

By Mureji Fatunde

A team led by Harvard computer scientists, including two undergraduate students, has developed a new tool that could lead to increased security and enhanced performance for commonly used web and mobile applications.

Called RockSalt, the clever bit of code can verify that native computer programming languages comply with a particular security policy.

Presented at the ACM Conference on Programming Language Design and Implementation (PLDI) in Beijing, in June, RockSalt was created by Greg Morrisett, Allen B. Cutting Professor of Computer Science at the Harvard School of Engineering and Applied Sciences (SEAS), two of his undergraduate students Edward Gan '13 and Joseph Tassarotti '13, former postdoctoral fellow Jean-Baptiste Tristan (now at Oracle), and Gang Tan of Lehigh University.

''When a user opens an external application, such as Gmail or Angry Birds, web browsers such as Google Chrome typically run the program's code in an intermediate and safer language such as JavaScript,'' says Morrisett. ''In many cases it would be preferable to run native machine code directly.''

The use of native code, especially in an online environment, however, opens up the door to hackers who can exploit vulnerabilities and readily gain access to other parts of a computer or device. An initial solution to this problem was offered over a decade ago by computer scientists at the University of California, Berkeley, who developed software fault isolation (SFI).

Latest articles

The silicon-rich AI race: how Cisco’s G300 puts networking at the center of compute

The silicon-rich AI race: how Cisco’s G300 puts networking at the center of compute

Silver jumps nearly Rs 7,000/kg; gold rises Rs 1,600 as weak US retail data boosts rate-cut bets

Silver jumps nearly Rs 7,000/kg; gold rises Rs 1,600 as weak US retail data boosts rate-cut bets

Goldman Sachs doubles down on India, climbs Wall Street rankings in crowded deal market

Goldman Sachs doubles down on India, climbs Wall Street rankings in crowded deal market

Rahul Gandhi criticises India–US trade deal as tariffs on Indian goods rise to 18%

Rahul Gandhi criticises India–US trade deal as tariffs on Indian goods rise to 18%

MPS Board Member and Senior Treasury Official Resigns Amid Insider Trading Probe

MPS Board Member and Senior Treasury Official Resigns Amid Insider Trading Probe

Eutelsat Secures €1 Billion Financing for OneWeb Satellite Procurement

Eutelsat Secures €1 Billion Financing for OneWeb Satellite Procurement

Tencent, Tesla Team Up on WeChat-Linked In-Car Features in China

Tencent, Tesla Team Up on WeChat-Linked In-Car Features in China

Australia presses Roblox over child safety concerns, regulator signals possible fines

Australia presses Roblox over child safety concerns, regulator signals possible fines

Cisco Unveils AI Networking Chip to Strengthen Position in Data Centre Boom

Cisco Unveils AI Networking Chip to Strengthen Position in Data Centre Boom