Secure Coding mailing list archives

Re: [External] Re: SearchSecurity: Dynamism


From: Alfonso De Gregorio <adg () secyoure com>
Date: Tue, 8 Sep 2015 21:45:58 +0000

On Tue, Sep 8, 2015 at 7:44 PM, Gary McGraw <gem () cigital com> wrote:
As far as I know, Microsoft integrated some reference monitoring into their OS family under Fred Schneider’s 
guidance.  They called it “inline reference monitoring” and I believe they still use it.

A related work by Microsoft is BrowserShield, an inline reference
monitor for JavaScript:

  BrowserShield: Vulnerability-Driven Filtering of Dynamic HTML
  http://research.microsoft.com/en-us/projects/shield/#browsershield

-- Alfonso

_______________________________________________
Secure Coding mailing list (SC-L) SC-L () securecoding org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates
_______________________________________________

Current thread: