DATS - data containers for web applications
File(s)codoms-bubbles.pdf (837.06 KB)
Accepted version
Author(s)
Hunger, Casen
Vilanova, Lluis
Papamanthou, Charalampos
Etsion, Yoav
Tiwari, Mohit
Type
Conference Paper
Abstract
Data containers enable users to control access to their data while untrusted applications compute on it. However, they require replicating an application inside each container - compromising functionality, programmability, and performance. We propose DATS - a system to run web applications that retains application usability and efficiency through a mix of hardware capability enhanced containers and the introduction of two new primitives modeled after the popular model-view-controller (MVC) pattern. (1) DATS introduces a templating language to create views that compose data across data containers. (2) DATS uses authenticated storage and confinement to enable an untrusted storage service, such as memcached and deduplication, to operate on plain-text data across containers. These two primitives act as robust declassifiers that allow DATS to enforce non-interference across containers, taking large applications out of the trusted computing base (TCB). We showcase eight different web applications including Gitlab and a Slack-like chat, significantly improve the worst-case overheads due to application replication, and demonstrate usable performance for common-case usage.
Date Issued
2018-03-23
Date Acceptance
2017-11-13
Citation
ASPLOS '18: Proceedings of the Twenty-Third International Conference on Architectural Support for Programming Languages and Operating Systems, 2018, pp.722-736
ISBN
978-1-4503-4911-6
Publisher
ACM
Start Page
722
End Page
736
Journal / Book Title
ASPLOS '18: Proceedings of the Twenty-Third International Conference on Architectural Support for Programming Languages and Operating Systems
Copyright Statement
© 2018 ACM. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in ASPLOS '18: Proceedings of the Twenty-Third International Conference on Architectural Support for Programming Languages and Operating Systems (March 2018) https://dl.acm.org/doi/10.1145/3173162.3173213
Source
Architectural Support for Programming Languages and Operating Systems (ASPLOS)
Subjects
Science & Technology
Technology
Computer Science, Software Engineering
Computer Science
Operating systems security
web application security
information flow control
information declassification
Software Engineering
Publication Status
Published
Start Date
2018-03-24
Finish Date
2018-03-28
Coverage Spatial
Williamsburg VA USA