SHILL: A Secure Shell Scripting Language

DSpace/Manakin Repository

SHILL: A Secure Shell Scripting Language

Citable link to this page


Title: SHILL: A Secure Shell Scripting Language
Author: Moore, Scott David; Dimoulas, Christos; King, Daniel; Chong, Stephen N

Note: Order does not necessarily reflect citation order of authors.

Citation: Moore, Scott, Christos Dimoulas, Dan King, and Stephen Chong. 2014. "Shill: A Secure Shell Scripting Language." In Proceedings of the 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI '14), Broomfield, CO, October 6-8, 2014: 183-199.
Full Text & Related Files:
Abstract: The Principle of Least Privilege suggests that software should be executed with no more authority than it requires to accomplish its task. Current security tools make it difficult to apply this principle: they either require significant modifications to applications or do not facilitate reasoning about combining untrustworthy components. We propose SHILL, a secure shell scripting language. SHILL scripts enable compositional reasoning about security through contracts that limit the effects of script execution, including the effects of programs invoked by the script. SHILL contracts are declarative security policies that act as documentation for consumers of SHILL scripts, and are enforced through a combination of language design and sandboxing. We have implemented a prototype of SHILL for FreeBSD and used it for several case studies including a grading script and a script to download, compile, and install software. Our experience indicates that SHILL is a practical and useful system security tool, and can provide fine-grained security guarantees.
Published Version:
Terms of Use: This article is made available under the terms and conditions applicable to Other Posted Material, as set forth at
Citable link to this page:
Downloads of this work:

Show full Dublin Core record

This item appears in the following Collection(s)


Search DASH

Advanced Search