Build It Break It: Measuring and Comparing Development Security
Total Page:16
File Type:pdf, Size:1020Kb
Load more
Recommended publications
-
Functional Programming at Facebook
Functional Programming at Facebook Chris Piro, Eugene Letuchy Commercial Users of Functional Programming (CUFP) Edinburgh, Scotland ! September "##$ Agenda ! Facebook and Chat " Chat architecture # Erlang strengths $ Setbacks % What has worked Facebook The Facebook Environment The Facebook Environment ▪ The web site ▪ More than 250 million active users ▪ More than 3.5 billion minutes are spent on Facebook each day The Facebook Environment ▪ The web site ▪ More than 250 million active users ▪ More than 3.5 billion minutes are spent on Facebook each day ▪ The engineering team ▪ Fast iteration: code gets out to production within a week ▪ Polyglot programming: interoperability with Thrift ▪ Practical: high-leverage tools win Using FP at Facebook Using FP at Facebook ▪ Erlang ▪ Chat backend (channel servers) ▪ Chat Jabber interface (ejabberd) ▪ AIM presence: a JSONP validator Using FP at Facebook ▪ Erlang ▪ Chat backend (channel servers) ▪ Chat Jabber interface (ejabberd) ▪ AIM presence: a JSONP validator ▪ Haskell ▪ lex-pass: PHP parse transforms ▪ Lambdabot ▪ textbook: command line Facebook API client ▪ Thrift binding Thrift Thrift ▪ An efficient, cross-language serialization and RPC framework Thrift ▪ An efficient, cross-language serialization and RPC framework ▪ Write interoperable servers and clients Thrift ▪ An efficient, cross-language serialization and RPC framework ▪ Write interoperable servers and clients ▪ Includes library and code generator for each language Thrift ▪ An efficient, cross-language serialization and RPC framework ▪ Write -
The Third Annual ICFP Programming Contest
The Third Annual ICFP Programming Contest August 26 – 29, 2000 (Version 1.18) 1 The problem This year’s ICFP programming challenge is to implement a ray tracer. The input to the ray tracer is a scene description written in a simple functional language, called GML. Execution of a GML program produces zero, or more, image files, which are in PPM format. A web page of sample images, along with the GML inputs that were used to produce them, is linked off of the contest home page. The feature set of GML is organized into three tiers. Submissions must implement the first tier of features and extra credit will be given to submissions that implement the second or third tiers. Submissions will be evaluated on three scales: correctness of the produced images, run-time performance, and the tier of implemented GML features. GML has primitives for defining simple geometric objects (e.g., planes, spheres, and cubes) and lighting sources. The surface properties used to render the objects are specified as functions in GML itself. In addition to supporting scene description, GML also has a render operator that renders a scene to an image file. For each pixel in the output image, the render command must compute a color. Conceptually, this color is computed by tracing the path of the light backwards from the eye of the viewer, to where it bounced off an object, and ultimately back to the light sources. This document is organized as follows. Section 2 describes the syntax and general semantics of the modeling language. It is followed by Section 3, which describes those aspects of the language that are specific to ray tracing. -
ICFP Programming Contest 2010 International Cars and Fuels Production
About Contest Task Running the Contest Background Winners Future ICFP Programming Contest 2010 International Cars and Fuels Production Bertram Felgenhauer, University of Innsbruck, Austria Johannes Waldmann, HTWK Leipzig, Germany June 18–21, 2010 Felgenhauer, Waldmann ICFP Programming Contest 2010 1/31 About Contest Task Running the Contest Background Winners Future About the ICFP Programming Contest programming, problem solving, fun annual contest, since 1998 sponsored by ICFP conference/ACM 2010 contest hosted by HTWK Leipzig, Germany contest format 72 hours (June 18, 12:00 – June 21, 12:00 GMT) participation online, international teams allowed no fixed programming language lightning division (first 24 hours) Felgenhauer, Waldmann ICFP Programming Contest 2010 2/31 earn money by (efficiently) solving instances, or creating instances (with solution, which is hard to find) income tax (devaluates earnings by 1/2 per day) About Contest Task Running the Contest Background Winners Future Contest Task storyline: market for cars (= problem instance) (public) fuels (= problem solution) (private) Felgenhauer, Waldmann ICFP Programming Contest 2010 3/31 About Contest Task Running the Contest Background Winners Future Contest Task storyline: market for cars (= problem instance) (public) fuels (= problem solution) (private) earn money by (efficiently) solving instances, or creating instances (with solution, which is hard to find) income tax (devaluates earnings by 1/2 per day) Felgenhauer, Waldmann ICFP Programming Contest 2010 3/31 About Contest Task -
ICFP 2009 Final Program
ICFP 2009 Final Program Monday, August 31, 2009 Tuesday, September 1, 2009 Wednesday, September 2, 2009 Invited Talk (Chair: Andrew Tolmach) Invited Talk (Chair: Graham Hutton) Invited Talk (Chair: Lennart Augustsson) 9:00 Organizing Functional Code for Parallel Execution; or, 9:00 Lambda, the Ultimate TA: Using a Proof Assistant to 9:00 Commutative Monads, Diagrams and Knots foldl and foldr Considered Slightly Harmful Teach Programming Language Foundations Dan Piponi; Industrial Light & Magic Guy L. Steele, Jr.; Sun Microsystems Benjamin C. Pierce; University of Pennsylvania 10:00 Break 10:00 Break 10:00 Break Session 11 (Chair: Ralf Hinze) Session 1 (Chair: Shin-Cheng Mu) Session 6 (Chair: Xavier Leroy) 10:25 Generic Programming with Fixed Points for Mutually 10:25 Functional Pearl: La Tour D’Hano¨ı 10:25 A Universe of Binding and Computation Recursive Datatypes Ralf Hinze; University of Oxford Daniel Licata and Robert Harper; Carnegie Mellon University Alexey Rodriguez Yakushev1, Stefan Holdermans2, Andres 2 3 10:50 Purely Functional Lazy Non-deterministic Program- 10:50 Non-Parametric Parametricity L¨oh , Johan Jeuring ; 1Vector Fabrics B.V., 2Utrecht University, ming Georg Neis, Derek Dreyer, Andreas Rossberg; MPI-SWS 3Utrecht University, Open University of the Netherlands Sebastian Fischer1, Oleg Kiselyov2, Chung-chieh Shan3; 11:15 Break 10:50 Attribute Grammars Fly First-Class: How to do As- 1Christian-Albrechts University, 2FNMOC, 3Rutgers University Session 7 (Chair: Robby Findler) pect Oriented Programming in Haskell 11:15 Break -
Revolutionary Betrayal: the Fall of King George III in the Experience Of
LIBERTY UNIVERSITY REVOLUTIONARY BETRAYAL: THE FALL OF KING GEORGE III IN THE EXPERIENCE OF POLITICIANS, PLANTERS, AND PREACHERS A THESIS SUBMITTED TO THE FACULTY OF THE HISTORY DEPARTMENT IN CANDIDACY FOR THE DEGREE OF MASTER OF HISTORY BY BENJAMIN J. BARLOWE LYNCHBURG, VIRGINIA APRIL 2013 Table of Contents Introduction ......................................................................................................... 1 Chapter 1: “Great Britain May Thank Herself:” King George III, Congressional Delegates, and American Independence, 1774-1776 .................................... 11 Chapter 2: Master and Slave, King and Subject: Southern Planters and the Fall of King George III ....................................................................................... 41 Chapter 3: “No Trace of Papal Bondage:” American Patriot Ministers and the Fall of King George III ................................................................................ 62 Conclusion ........................................................................................................ 89 Bibliography ...................................................................................................... 94 1 Introduction When describing the imperial crisis of 1763-1776 between the British government and the American colonists, historians often refer to Great Britain as a united entity unto itself, a single character in the imperial conflict. While this offers rhetorical benefits, it oversimplifies the complex constitutional relationship between the American -
Stephanie Weirich –
Stephanie Weirich School of Engineering and Science, University of Pennsylvania Levine 510, 3330 Walnut St, Philadelphia, PA 19104 215-573-2821 • [email protected] July 13, 2021 Positions University of Pennsylvania Philadelphia, Pennsylvania ENIAC President’s Distinguished Professor September 2019-present Galois, Inc Portland, Oregon Visiting Scientist June 2018-August 2019 University of Pennsylvania Philadelphia, Pennsylvania Professor July 2015-August 2019 University of Pennsylvania Philadelphia, Pennsylvania Associate Professor July 2008-June 2015 University of Cambridge Cambridge, UK Visitor August 2009-July 2010 Microsoft Research Cambridge, UK Visiting Researcher September-November 2009 University of Pennsylvania Philadelphia, Pennsylvania Assistant Professor July 2002-July 2008 Cornell University Ithaca, New York Instructor, Research Assistant and Teaching AssistantAugust 1996-July 2002 Lucent Technologies Murray Hill, New Jersey Intern June-July 1999 Education Cornell University Ithaca, NY Ph.D., Computer Science 2002 Cornell University Ithaca, NY M.S., Computer Science 2000 Rice University Houston, TX B.A., Computer Science, magnum cum laude 1996 Honors ○␣ SIGPLAN Robin Milner Young Researcher award, 2016 ○␣ Most Influential ICFP 2006 Paper, awarded in 2016 ○␣ Microsoft Outstanding Collaborator, 2016 ○␣ Penn Engineering Fellow, University of Pennsylvania, 2014 ○␣ Institute for Defense Analyses Computer Science Study Panel, 2007 ○␣ National Science Foundation CAREER Award, 2003 ○␣ Intel Graduate Student Fellowship, 2000–2001 -
Stephanie Weirich –
Stephanie Weirich School of Engineering and Science, University of Pennsylvania Levine 510, 3330 Walnut St, Philadelphia, PA 19104 215-573-2821 • [email protected] • June 21, 2014 Education Cornell University Ithaca, NY Ph.D., Computer Science August 2002 Cornell University Ithaca, NY M.S., Computer Science August 2000 Rice University Houston, TX B.A., Computer Science May 1996 magnum cum laude Positions Held University of Pennsylvania Philadelphia, Pennsylvania Associate Professor July 2008-present University of Cambridge Cambridge, UK Visitor August 2009-July 2010 Microsoft Research Cambridge, UK Visiting Researcher September-November 2009 University of Pennsylvania Philadelphia, Pennsylvania Assistant Professor July 2002-July 2008 Cornell University Ithaca, New York Instructor, Research Assistant and Teaching Assistant August 1996-July 2002 Lucent Technologies Murray Hill, New Jersey Intern June-July 1999 Research Interests Programming languages, Type systems, Functional programming, Generic programming, De- pendent types, Program verification, Proof assistants Honors Penn Engineering Fellow, University of Pennsylvania, 2014. Institute for Defense Analyses Computer Science Study Panel, 2007. National Science Foundation CAREER Award, 2003. Intel Graduate Student Fellowship, 2000–2001. National Science Foundation Graduate Research Fellowship, 1996–1999. CRA-W Distributed Mentorship Project Award, 1996. Microsoft Technical Scholar, 1995–1996. Technical Society Membership Association for Computing Machinery, 1998-present ACM SIGPLAN, 1998-present ACM SIGLOG, 2014-present IFIP Working Group 2.8 (Functional Programming), 2003-present IFIP Working Group 2.11 (Program Generation), 2007-2012 Teaching Experience CIS 120 - Programming Languages and Techniques I CIS 552 - Advanced Programming CIS 670/700 - Advanced topics in Programming Languages CIS 500 - Software Foundations CIS 341 - Programming Languages Students Dissertation supervision................................................................................... -
SEINFELD Revision #1 (Pink) 34. “The Contest” Oct 26 1992 (2/P)
SEINFELD Revision #1 (pink) 34. “The Contest” Oct 26 1992 (2/P) (Jerry, George, Elaine) ACT TWO SCENE P INT. COFFEE SHOP - DAY (3) JERRY AND GEORGE JERRY So the nurse gave her a sponge bath? GEORGE Yeah. Everynight at 6:30. The nurse is gorgeous. Then I got a glimpse of the patient. I was going nuts. JERRY So, I guess you’ll be back in that hospital. GEORGE Well, my mother... JERRY But you’re still master of your domain. SEINFELD Revision #1 (pink) 35. “The Contest” Oct 26 1992 (2/P) GEORGE I’m king of the county. What about you? JERRY Lord of the manor. ELAINE ENTERS, SITS. ELAINE ...John F. Kennedy Jr. JERRY What? ELAINE He was in the aerobics class. He was exercising in front of me. JERRY Really? Did you talk to him? ELAINE You don’t understand. He worked out in front of me. When the class was over I timed my walk to the door so we’d get there at the same moment. So he says to me, “Quite a workout.” GEORGE “Quite a workout?” What did you say? ELAINE I said, “yeah.” SEINFELD Revision #1 (pink) 36. “The Contest” Oct 26 1992 (2/P) JERRY Good one. ELAINE Then I showered and dressed and I saw him again on the way out. So he holds the door open for me and he says, “Which way are you walking?” and I said, “Which way are you walking?” And he said, “That way.” And I said, “Well, isn’t that a coincidence?” Of course I was going in the opposite direction.. -
Build It, Break It, Fix It: Contesting Secure Development
Build It, Break It, Fix It: Contesting Secure Development Andrew Ruef Michael Hicks James Parker Dave Levin Michelle L. Mazurek Piotr Mardziely University of Maryland yCarnegie Mellon University experts have long advocated that achieving security in a computer system requires treating security as a first-order ABSTRACT design goal [32], and is not something that can be added after the fact. As such, we should not assume that good Typical security contests focus on breaking or mitigating the breakers will necessarily be good builders [23], nor that top impact of buggy systems. We present the Build-it, Break-it, coders necessarily produce secure systems. Fix-it (BIBIFI) contest, which aims to assess the ability to This paper presents Build-it, Break-it, Fix-it (BIBIFI), securely build software, not just break it. In BIBIFI, teams a new security contest with a focus on building secure sys- build specified software with the goal of maximizing correct- tems. A BIBIFI contest has three phases. The first phase, ness, performance, and security. The latter is tested when Build-it, asks small development teams to build software ac- teams attempt to break other teams' submissions. Win- cording to a provided specification that includes security ners are chosen from among the best builders and the best goals. The software is scored for being correct, efficient, and breakers. BIBIFI was designed to be open-ended|teams feature-ful. The second phase, Break-it, asks teams to find can use any language, tool, process, etc. that they like. As defects in other teams' build-it submissions. Reported de- such, contest outcomes shed light on factors that correlate fects, proved via test cases vetted by an oracle implementa- with successfully building secure software and breaking inse- tion, benefit a break-it team's score and penalize the build-it cure software. -
Daniel R. Licata
Daniel R. Licata Personal E-mail: [email protected] Information: Web: http://www.cs.cmu.edu/~drl/ Home Address: 79 Merit Ln. Princeton, NJ 08540 Mobile Phone: +1 (412) 889-0106 Academic Institute for Advanced Study 2012-2013 Background: Member. Post-doc for a year-long special program on Homotopy Type Theory. Carnegie Mellon University 2011-2012 Teaching Post-doctoral Fellow. Designed and delivered a new intro. course, Principles of Functional Programming. Carnegie Mellon University 2004 to 2011 PhD in Computer Science. Advised by Robert Harper. Brown University 2000 to 2004 Bachelor of Science in Mathematics and Computer Science. Awards & FoLLI E.W. Beth Dissertation Award, 2012 Winner Fellowships: CMU SCS Dissertation Award, Honorable Mention, 2011 Pradeep Sindhu Computer Science Fellowship, Carnegie Mellon University, 2009-2010. Finalist for Computing Research Association Outstanding Undergraduate Award, 2004. Funding Cowrote NSF Grant CCF-1116703: Foundations and Applications of Higher-Dimensional Type Theory, which funded part of my post-doc. Cowrote NSF Grant CCF-0702381: Integrating Types and Verification, which funded part of my dissertation work. Publications: Dissertation Dependently Typed Programming with Domain-Specific Logics. February, 2011. Committee: Robert Harper, Frank Pfenning, Karl Crary, Greg Morrisett Journal Articles Robert Harper and Daniel R. Licata. Mechanizing Metatheory in a Logical Framework. Journal of Functional Programming. 17(4-5), pp 613-673, July 2007. Conference Papers Calculating the Fundamental Group of the Circle in Homotopy Type Theory. Daniel R. Licata and Michael Shulman. IEEE Symposium on Logic in Computer Science (LICS), June, 2013. Canonicity for 2-Dimensional Type Theory. Daniel R. Licata and Robert Harper. -
Universi^ Micrcxilms Liitemational 300 N
INFORMATION TO USERS This reproduction was made from a copy of a document sent to us for microfilming. While the most advanced technology has been used to photograph and reproduce this document, the quality of the reproduction is heavily dependent upon the quality of the material submitted. The following explanation of techniques is provided to help clarify markings or notations which may appear on this reproduction. 1. The sign or “target” for pages apparently lacking from the document photographed is “Missing Page(s)”. If it was possible to obtain the missing page(s) or section, they are spliced into the film along with adjacent pages. This may have necessitated cutting through an image and duplicating adjacent pages to assure complete continuity. 2. When an image on the film is obliterated with a round black mark, it is an indication of either blurred copy because of movement during exposure, duplicate copy, or copyrighted materials that should not have been filmed. For blurred pages, a good image of the page can be found in the adjacent frame. If copyrighted materials were deleted, a target note will appear listing the pages in the adjacent frame. 3. When a map, drawing or chart, etc., is part of the material being photographed, a definite method of “sectioning” the material has been followed. It is customary to begin filming at the upper left hand comer of a large sheet and to continue from left to right in equal sections with small overlaps. If necessary, sectioning is continued again—beginning below the first row and continuing on until complete. -
Chung-Chieh Shan 單中杰 Luddy Hall, Room 3018 (812) 856-4400 Phone 700 N
Chung-chieh Shan ®-p Luddy Hall, Room 3018 (812) 856-4400 phone 700 N. Woodlawn Avenue (812) 855-4829 fax Bloomington, IN 47408-3901 [email protected] Associate Professor, Department of Computer Science, Indiana University (2019–) Assistant Professor, Department of Computer Science, Indiana University (2013–2019) Researcher, Department of Computer Science, University of Tsukuba (Spring 2012) Visiting Assistant Professor, Department of Linguistics, Cornell University (Fall 2011) Assistant Professor, Department of Computer Science and Center of Cognitive Science, Rutgers University (2005–2011) Research I study what things mean that matter. I work to tap into and enhance the amazing human ability to create concepts, combine concepts, and share concepts, by lining up formal representations and what they represent. To this end, in the short term, I develop programming languages that divide what to do and how to do it into modules that can be built and reused separately. In particular, I develop so-called probabilistic programming languages, which divide stochastic models and inference algorithms into modules that can be built and reused separately. In the long term, I hope to supplant first-order logic by something that does not presuppose a fact of the matter what things there are, though there may be a fact of the matter what stuff there is. Teaching Introduction to computer science (BL CSCI C211, Fall 2017, Spring 2018, Fall 2018, Spring 2019, Fall 2019) Probabilistic programming (Invited course at the Scottish school on programming languages