Blogs

RSS

An aggregation of our Blog Roll, made up of acmqueue authors.   more

All Postings, Robert N. M. Watson:  (15 posts)

Source blog: Light Blue Touchpaper

Wed, 26 Feb 2014 13:32:51 UTC

Research Assistants and Associates in OS, Compiler and CPU Security

Posted By Robert N. M. Watson

We are pleased to announce a job ad for two new research assistants or post-doctoral research associates working on our CTSRD Project, whose target research areas include OS, compiler, and CPU security. This is a joint project between the University of Cambridge’s Security, NetOS, and Computer Architecture research groups, as well as the Computer Science [...]

Fri, 20 Dec 2013 23:02:20 UTC

2013 Capsicum year in review

Posted By Robert N. M. Watson

It’s been a busy year for Capsicum, practical capabilities for UNIX, so a year-end update seemed in order: The FreeBSD Foundation and Google jointly funded a Capsicum Integration Project that took place throughout 2013 — described by Foundation project technical director Ed Maste in a recent blog article. Pawel Jakub Dawidek refined several Capsicum APIs, improving [...]

Sun, 15 Sep 2013 09:39:25 UTC

Google funding of open-source security projects

Posted By Robert N. M. Watson

I was pleased to contribute to a recent blog article by Ben Laurie, a frequent collaborator with the Cambridge security group, on the Google Open Source Programs Office blog. We describe open-source security work OSPO has sponsored over the last couple of years, including our joint work on Capsicum, and its followup projects funded jointly [...]

Tue, 09 Apr 2013 11:57:32 UTC

Job ad: pre- and post-doctoral posts in processor, operating system, and compiler security

Posted By Robert N. M. Watson

The CTSRD Project is advertising two posts in processor, operating system, and compiler security. The first is a research assistant position, suitable for candidates who may not have a research background, and the second is a post-doctoral research associate position suitable for candidates who have completed (or will shortly complete) a PhD in computer science [...]

Wed, 30 Jan 2013 16:11:34 UTC

CACM: A decade of OS access-control extensibility

Posted By Robert N. M. Watson

Operating-system access control technology has undergone a remarkable transformation over the last fifteen years as appliance, embedded, and mobile device vendors transitioned from dedicated “embedded operating systems” to general-purpose ones — often based on open-source UNIX and Linux variants. Device vendors look to upstream operating system authors to provide the critical low-level software foundations for [...]

Wed, 02 Jan 2013 22:02:54 UTC

Interviews on the clean-slate design argument

Posted By Robert N. M. Watson

Over the past two years, Peter G. Neumann and I, along with a host of collaborators at SRI International and the University of Cambridge Computer Laboratory, have been pursuing CTSRD, a joint computer-security research project exploring fundamental revisions to CPU design, operating systems, and application program structure. Recently we’ve been talking about the social, economic, [...]

Mon, 10 Dec 2012 20:54:03 UTC

CFP: Runtime Environments, Systems, Layering and Virtualized Environments (RESoLVE 2013)

Posted By Robert N. M. Watson

This year, we presented two papers at RESoLVE 2012 relating to the structure of operating systems and hardware, one focused on CPU instruction set security features out of our CTSRD project, and another on efficient and reconfigurable communications in data centres out of our MRC2 project. I’m pleased to announce the Call for Papers for RESoLVE [...]

Tue, 16 Oct 2012 13:07:29 UTC

ACM Queue interview on research into the hardware-software interface

Posted By Robert N. M. Watson

ACM Queue has posted my August 2012 interview on research into the hardware-software interface. We discuss the importance of a whole-stack view in addressing contemporary application security problems, which are often grounded in how we represent and execute software over lower-level substrates. We need to consider CPU design, operating systems, programming languages, applications, and formal [...]

Sun, 10 Jun 2012 12:05:34 UTC

Call for papers: Workshop on Adaptive Host and Network Security

Posted By Robert N. M. Watson

Stu Wagner, Bob Laddaga, and I are pleased to announce the call for papers for a new Workshop on Adaptive Host and Network Security, to take place at the Sixth IEEE Conference on Self-Adaptive and Self-Organizing Systems in September 2012 in Lyon, France. Over the past decade the threat of cyber attacks on critical commercial and [...]

Wed, 21 Mar 2012 15:00:52 UTC

Job ad: post-doctoral researcher in security, operating systems, computer architecture

Posted By Robert N. M. Watson

We are pleased to announce a job opening at the University of Cambridge Computer Laboratory for a post-doctoral researcher working in the areas of security, operating systems, and computer architecture. Research Associate in compiler-assisted instrumentation of operating system kernels University of Cambridge – Faculty of Computer Science and Technology Salary: £27,578-£35,938 pa The funds for this post are available [...]

Wed, 14 Mar 2012 21:06:49 UTC

Capsicum in CACM Research Highlights

Posted By Robert N. M. Watson

The Research Highlights section of Communications of the ACM from March 2012 features two articles on Capsicum, collaborative research by the Cambridge security group and Google on capability-oriented security for contemporary operating systems. The first, Technical Perspective: The Benefits of Capability-Based Protection by Steven Gribble, considers the value of capability systems (such as Capsicum) in [...]

Thu, 23 Feb 2012 23:05:32 UTC

Three-paper Thursday: capability systems

Posted By Robert N. M. Watson

This week, my contribution to our three-paper Thursday research reading list series is on capability systems. Capabilities are unforgeable tokens of authority — capability systems are hardware, operating, or programming systems in which access to resources can occur only using capabilities. Capability system research in the 1970s motivated many fundamental insights into practical articulations of [...]

Mon, 30 Jan 2012 10:06:12 UTC

FreeBSD 9.0 ships with experimental Capsicum support

Posted By Robert N. M. Watson

Jon Anderson, Ben Laurie, Kris Kennaway, and I were pleased to see prominent mention of Capsicum in the recent FreeBSD 9.0 press release: Continuing its heritage of innovating in the area of security research, FreeBSD 9.0 introduces Capsicum. Capsicum is a lightweight framework which extends a POSIX UNIX kernel to support new security capabilities and adds [...]

Tue, 06 Dec 2011 17:38:51 UTC

Job ad: post-doctoral researcher in security, operating systems, computer architecture

Posted By Robert N. M. Watson

We are very pleased to announce a job opening at the University of Cambridge Computer Laboratory for a post-doctoral researcher working in the areas of security, operating systems, and computer architecture.

Thu, 12 Aug 2010 02:57:37 UTC

Capsicum: practical capabilities for UNIX

Posted By Robert N. M. Watson

Today, Jonathan Anderson, Ben Laurie, Kris Kennaway, and I presented Capsicum: practical capabilities for UNIX at the 19th USENIX Security Symposium in Washington, DC; the slides can be found on the Capsicum web site. We argue that capability design principles fill a gap left by discretionary access control (DAC) and mandatory access control (MAC) in [...]