Conference Publications
Implicit Flows: Can't Live With 'Em, Can't Live Without
'Em. Dave King, Boniface Hicks, Trent Jaeger, Michael Hicks.
Proceedings of the 4th International Conference on Information
Systems Security (ICISS 2008). To appear.
Effective Blame for Information-Flow Violations. Dave
King, Trent Jaeger, Somesh Jha, Sanjit A. Seshia. Proceedings of
the 16th ACM SIGSOFT International Symposium on Foundations of
Software Engineering (FSE 2008). [pdf, tech report]
Verifying the Compliance of Trusted Programs. Sandra
Rueda, Dave King, Trent Jaeger. Proceedings of the 17th Annual
USENIX Security Symposium (USENIX '08). July 2008. [pdf]
Mining Security-Sensitive Operations in Legacy Code using
Concept Analysis. Vinod Ganapathy, Dave King, Trent Jaeger,
Somesh Jha. Proceedings of the 29th International Conference on
Software Engineering (ICSE '07), May 2007. [pdf]
Leveraging IPsec for Mandatory Access Control Across
Systems. Trent Jaeger, David H. King, Kevin Butler, Serge Hallyn, Joy Latten, and Xiaolan Zhang.
Second IEEE International Conference on Security and
Privacy in Communication Networks (SecureComm), August 2006. [pdf]
Workshop Publications
Jifclipse: Development Tools for Security-Typed
Languages. Boniface Hicks, Dave King, and Patrick McDaniel.
Proceedings of the ACM SIGPLAN Workshop on Programming Languages and
Analysis for Security (PLAS), June 2007. [pdf; software release (new
version; wishlist; send us your
bugs!)
Trusted Declassification: High-level policy for a
security-typed language. Boniface Hicks, Dave King, Patrick
McDaniel, and Michael Hicks. Proceedings of the ACM SIGPLAN
Workshop on Programming Languages and Analysis for Security (PLAS),
June 2006. [pdf]
Technical Reports
Reduction of the compliance problem to the graph isomorphism
problem. Sandra Rueda, Dave King, and Trent Jaeger. Technical
Report NAS-TR-0081-2007, Network and Security Research Center, CSE
Department. The Pennsylvania State University. October 2007.
(superceded by USENIX Security 2008 publication)
On Automatic Placement of Declassifiers for Information-Flow
Security. Dave King, Susmit Jha, Trent Jaeger, Somesh Jha, and and
Sanjit A. Seshia. Technical Report NAS-TR-0083-2007, Network and
Security Research Center, November 2007. Updated January 2008. [pdf]
Effective Blame for Information-Flow Violations. Dave King,
Trent Jaeger, Somesh Jha, and Sanjit A. Seshia. Technical Report
NAS-TR-0069-2007, Network and Security Research Center, May
2007. Updated March 2008. [pdf] (superceded by FSE 2008 publication)
Non-Refereed Publications
Use-Based Inference of Reference Polymorphism. Dave King
and John Hannan. In the Pre-proceedings of the 8th Symposium on Trends in
Functional Programming, April 2007. [extended abstract;
draft paper; pre-tech report; slides]
|