{"id":"https://openalex.org/W2969614198","doi":"https://doi.org/10.1109/eurosp.2019.00016","title":"Information-Flow Control for Database-Backed Applications","display_name":"Information-Flow Control for Database-Backed Applications","publication_year":2019,"publication_date":"2019-06-01","ids":{"openalex":"https://openalex.org/W2969614198","doi":"https://doi.org/10.1109/eurosp.2019.00016","mag":"2969614198"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1109/eurosp.2019.00016","pdf_url":"https://ieeexplore.ieee.org/ielx7/8790377/8806708/08806751.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://ieeexplore.ieee.org/ielx7/8790377/8806708/08806751.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5069694679","display_name":"Marco Guarnieri","orcid":"https://orcid.org/0000-0001-5767-555X"},"institutions":[{"id":"https://openalex.org/I4210162154","display_name":"IMDEA Software","ror":"https://ror.org/04xvfkh51","country_code":"ES","type":"facility","lineage":["https://openalex.org/I105140100","https://openalex.org/I4210162154"]}],"countries":["ES"],"is_corresponding":false,"raw_author_name":"Marco Guarnieri","raw_affiliation_strings":["IMDEA Software Institute"],"affiliations":[{"raw_affiliation_string":"IMDEA Software Institute","institution_ids":["https://openalex.org/I4210162154"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5073362414","display_name":"Musard Balliu","orcid":"https://orcid.org/0000-0001-6005-5992"},"institutions":[{"id":"https://openalex.org/I86987016","display_name":"KTH Royal Institute of Technology","ror":"https://ror.org/026vcq606","country_code":"SE","type":"funder","lineage":["https://openalex.org/I86987016"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Musard Balliu","raw_affiliation_strings":["KTH Royal Institute of Technology"],"affiliations":[{"raw_affiliation_string":"KTH Royal Institute of Technology","institution_ids":["https://openalex.org/I86987016"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5044906965","display_name":"Daniel Schoepe","orcid":"https://orcid.org/0009-0006-1187-9569"},"institutions":[{"id":"https://openalex.org/I66862912","display_name":"Chalmers University of Technology","ror":"https://ror.org/040wg7k59","country_code":"SE","type":"funder","lineage":["https://openalex.org/I66862912"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Daniel Schoepe","raw_affiliation_strings":["Chalmers University of Technology"],"affiliations":[{"raw_affiliation_string":"Chalmers University of Technology","institution_ids":["https://openalex.org/I66862912"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025344654","display_name":"David Basin","orcid":"https://orcid.org/0000-0003-2952-939X"},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"funder","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"David Basin","raw_affiliation_strings":["ETH Zurich"],"affiliations":[{"raw_affiliation_string":"ETH Zurich","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5070340953","display_name":"Andrei Sabelfeld","orcid":null},"institutions":[{"id":"https://openalex.org/I66862912","display_name":"Chalmers University of Technology","ror":"https://ror.org/040wg7k59","country_code":"SE","type":"funder","lineage":["https://openalex.org/I66862912"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Andrei Sabelfeld","raw_affiliation_strings":["Chalmers University of Technology"],"affiliations":[{"raw_affiliation_string":"Chalmers University of Technology","institution_ids":["https://openalex.org/I66862912"]}]}],"institution_assertions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.594,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":15,"citation_normalized_percentile":{"value":0.887464,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":88,"max":89},"biblio":{"volume":null,"issue":null,"first_page":"79","last_page":"94"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10772","display_name":"Distributed systems and fault tolerance","score":0.9992,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.997,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/database-security","display_name":"Database security","score":0.5278737},{"id":"https://openalex.org/keywords/physical-data-model","display_name":"Physical data model","score":0.43837073},{"id":"https://openalex.org/keywords/database-administrator","display_name":"Database administrator","score":0.43634573}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8456279},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.7528287},{"id":"https://openalex.org/C118930307","wikidata":"https://www.wikidata.org/wiki/Q600590","display_name":"Tuple","level":2,"score":0.72131723},{"id":"https://openalex.org/C12439846","wikidata":"https://www.wikidata.org/wiki/Q4809258","display_name":"Database theory","level":3,"score":0.54938495},{"id":"https://openalex.org/C2778553114","wikidata":"https://www.wikidata.org/wiki/Q1035293","display_name":"Database security","level":2,"score":0.5278737},{"id":"https://openalex.org/C148840519","wikidata":"https://www.wikidata.org/wiki/Q1049878","display_name":"Database design","level":2,"score":0.49569857},{"id":"https://openalex.org/C187959359","wikidata":"https://www.wikidata.org/wiki/Q17113749","display_name":"Physical data model","level":5,"score":0.43837073},{"id":"https://openalex.org/C5968703","wikidata":"https://www.wikidata.org/wiki/Q267136","display_name":"Database model","level":3,"score":0.4383576},{"id":"https://openalex.org/C70236469","wikidata":"https://www.wikidata.org/wiki/Q1078262","display_name":"Database administrator","level":2,"score":0.43634573},{"id":"https://openalex.org/C78161392","wikidata":"https://www.wikidata.org/wiki/Q5227414","display_name":"Database testing","level":4,"score":0.41420195},{"id":"https://openalex.org/C54239708","wikidata":"https://www.wikidata.org/wiki/Q1329910","display_name":"View","level":3,"score":0.38307658},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.34080374},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C118615104","wikidata":"https://www.wikidata.org/wiki/Q121416","display_name":"Discrete mathematics","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1109/eurosp.2019.00016","pdf_url":"https://ieeexplore.ieee.org/ielx7/8790377/8806708/08806751.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},{"is_oa":true,"landing_page_url":"http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-249678","pdf_url":"https://kth.diva-portal.org/smash/get/diva2:1305447/FULLTEXT01","source":{"id":"https://openalex.org/S4306401560","display_name":"KTH Publication Database DiVA (KTH Royal Institute of Technology)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1109/eurosp.2019.00016","pdf_url":"https://ieeexplore.ieee.org/ielx7/8790377/8806708/08806751.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"display_name":"Peace, justice, and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.58}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":53,"referenced_works":["https://openalex.org/W1480909796","https://openalex.org/W1488890761","https://openalex.org/W1558832481","https://openalex.org/W1582983062","https://openalex.org/W1771153709","https://openalex.org/W1817610252","https://openalex.org/W1821830326","https://openalex.org/W1910149059","https://openalex.org/W1964985226","https://openalex.org/W1978267236","https://openalex.org/W1983142587","https://openalex.org/W2005421574","https://openalex.org/W2008074667","https://openalex.org/W2027822753","https://openalex.org/W2036463966","https://openalex.org/W2040581748","https://openalex.org/W2041937026","https://openalex.org/W2043226436","https://openalex.org/W2060710422","https://openalex.org/W2066684585","https://openalex.org/W2074935412","https://openalex.org/W2088958550","https://openalex.org/W2093397547","https://openalex.org/W2114917462","https://openalex.org/W2138158983","https://openalex.org/W2140250198","https://openalex.org/W2145653610","https://openalex.org/W2145846275","https://openalex.org/W2149465027","https://openalex.org/W2153684747","https://openalex.org/W2161824253","https://openalex.org/W2166449856","https://openalex.org/W2168686464","https://openalex.org/W2171182387","https://openalex.org/W2174103411","https://openalex.org/W2182564418","https://openalex.org/W2202148857","https://openalex.org/W2294395356","https://openalex.org/W2296605318","https://openalex.org/W2296887322","https://openalex.org/W2404393214","https://openalex.org/W2405761718","https://openalex.org/W246878872","https://openalex.org/W254902136","https://openalex.org/W2738444131","https://openalex.org/W2751848028","https://openalex.org/W2900152012","https://openalex.org/W3100118001","https://openalex.org/W3105803244","https://openalex.org/W3125174003","https://openalex.org/W4206031975","https://openalex.org/W4206358530","https://openalex.org/W4235779931"],"related_works":["https://openalex.org/W83150690","https://openalex.org/W2998585934","https://openalex.org/W2372613381","https://openalex.org/W2366660644","https://openalex.org/W2208781441","https://openalex.org/W2175786273","https://openalex.org/W2129469317","https://openalex.org/W2080297823","https://openalex.org/W1989645082","https://openalex.org/W1603211808"],"abstract_inverted_index":{"Securing":[0],"database-backed":[1,63],"applications":[2],"requires":[3],"tracking":[4,119],"information":[5,120],"across":[6],"the":[7,11,36,111,123],"application":[8],"program":[9],"and":[10,72,83,100,145],"database":[12,45,73,77,92,114],"together,":[13],"since":[14],"securing":[15],"each":[16],"component":[17],"in":[18,23],"isolation":[19],"may":[20,52],"still":[21],"result":[22],"an":[24,130],"overall":[25],"insecure":[26],"system.":[27],"Current":[28],"research":[29],"extends":[30],"language-based":[31],"techniques":[32],"with":[33],"models":[34],"capturing":[35],"database's":[37],"behavior.":[38],"This":[39],"research,":[40],"however,":[41],"relies":[42],"on":[43,149],"simplistic":[44],"models,":[46],"which":[47],"ignore":[48],"security-relevant":[49],"features":[50,115],"that":[51,94,109],"leak":[53],"sensitive":[54],"information.":[55],"We":[56,125,138],"propose":[57],"a":[58,90],"novel":[59],"security":[60],"monitor":[61,66,104,141],"for":[62,89,142],"applications.":[64],"Our":[65],"tracks":[67],"fine-grained":[68],"dependencies":[69],"between":[70],"variables":[71],"tuples":[74],"by":[75],"leveraging":[76],"theory":[78],"concepts":[79],"like":[80,98,116],"disclosure":[81,136],"lattices":[82],"query":[84],"determinacy.":[85],"It":[86],"also":[87,126],"accounts":[88],"realistic":[91],"model":[93],"supports":[95],"security-critical":[96],"constructs":[97],"triggers":[99],"dynamic":[101],"policies.":[102],"The":[103],"automatically":[105],"synthesizes":[106],"program-level":[107],"code":[108],"replicates":[110],"behavior":[112],"of":[113,133],"triggers,":[117],"thereby":[118],"flows":[121],"inside":[122],"database.":[124],"introduce":[127],"symbolic":[128],"tuples,":[129],"efficient":[131],"approximation":[132],"dependency-tracking":[134],"over":[135],"lattices.":[137],"implement":[139],"our":[140],"Scala":[143],"programs":[144],"demonstrate":[146],"its":[147],"effectiveness":[148],"four":[150],"case":[151],"studies.":[152]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2969614198","counts_by_year":[{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":1}],"updated_date":"2025-04-18T00:51:27.889112","created_date":"2019-08-29"}