<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jefferson&#039;s Wheel &#187; GuardRails</title>
	<atom:link href="http://www.jeffersonswheel.org/category/guardrails/feed" rel="self" type="application/rss+xml" />
	<link>https://www.jeffersonswheel.org</link>
	<description>Security Research at the University of Virginia</description>
	<lastBuildDate>Sun, 14 Oct 2018 03:12:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Congratulations Jonathan!</title>
		<link>https://www.jeffersonswheel.org/2013/congratulations-jonathan</link>
		<comments>https://www.jeffersonswheel.org/2013/congratulations-jonathan#comments</comments>
		<pubDate>Tue, 07 May 2013 00:08:21 +0000</pubDate>
		<dc:creator>David Evans</dc:creator>
				<category><![CDATA[Awards]]></category>
		<category><![CDATA[GuardRails]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.jeffersonswheel.org/?p=453</guid>
		<description><![CDATA[Jonathan Burket has been recognized with a CRA Outstanding Undergraduate Researcher Honorable Mention. This award recognizes outstanding research by undergraduate students in North America. Jonathan joined our research group as a first year student (recruited from cs1120) and has done several research projects focused on web security including working on GuardRails and leading a new [...]]]></description>
				<content:encoded><![CDATA[<p><img style="margin: 10px 10px" src="http://www.cs.virginia.edu/~evans/cs1120-f11/wp-content/uploads/2011/08/JBPicture.jpg" align="left"><br />
Jonathan Burket has been recognized with a <a href="http://www.cra.org/awards/undergrad/">CRA Outstanding Undergraduate Researcher</a> Honorable Mention.  This <a href="http://www.jeffersonswheel.org/awards">award</a> recognizes outstanding research by undergraduate students in North America.</p>
<p>Jonathan joined our research group as a first year student (recruited from <a href="http://www.cs.virginia.edu/~evans/cs1120-f09/">cs1120</a>) and has done several research projects focused on web security including working on <a href="http://guardrails.cs.virginia.edu">GuardRails</a> and leading a new research project on correlating web application state and requests with behavior such as database requests.</p>
<p>Congratulations to Jonathan!   </p>
]]></content:encoded>
			<wfw:commentRss>https://www.jeffersonswheel.org/2013/congratulations-jonathan/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Austin DeVinney featured in Radford News</title>
		<link>https://www.jeffersonswheel.org/2012/austin-devinney-featured-in-radford-news</link>
		<comments>https://www.jeffersonswheel.org/2012/austin-devinney-featured-in-radford-news#comments</comments>
		<pubDate>Tue, 07 Feb 2012 21:41:01 +0000</pubDate>
		<dc:creator>David Evans</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[GuardRails]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.jeffersonswheel.org/?p=419</guid>
		<description><![CDATA[Austin DeVinney, who worked with us on GuardRails last summer and presented a poster at USENIX Security Symposium, was featured in Radford&#8217;s College of Science and Technology newsletter. Information technology student Austin DeVinney&#8217;s interest and curiosity has paid off with a summer internship opportunity with cybersecurity expert and Associate Professor of Computer Science at the [...]]]></description>
				<content:encoded><![CDATA[<p>Austin DeVinney, who worked with us on <a href="http://guardrails.cs.virginia.edu">GuardRails</a> last summer and presented a poster at USENIX Security Symposium, was featured in Radford&#8217;s <em>College of Science and Technology</em> newsletter.</p>
<blockquote><p>
Information technology student Austin DeVinney&#8217;s interest and curiosity has paid off with a summer internship opportunity with cybersecurity expert and Associate Professor of Computer Science at the University of Virginia David Evans.
</p>
</blockquote>
<p>
The full article is here: <a href="http://www.radford.edu/content/dam/colleges/csat/home%20page%20docs/deans%20desk/Sept.%2022.%202011.pdf"><br />
<em>IT Student Presents Research at Prestigious Conference</em> [PDF]</a>.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.jeffersonswheel.org/2012/austin-devinney-featured-in-radford-news/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USENIX WebApps Paper</title>
		<link>https://www.jeffersonswheel.org/2011/usenix-webapps-paper</link>
		<comments>https://www.jeffersonswheel.org/2011/usenix-webapps-paper#comments</comments>
		<pubDate>Wed, 04 May 2011 18:27:54 +0000</pubDate>
		<dc:creator>David Evans</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[GuardRails]]></category>
		<category><![CDATA[Papers]]></category>

		<guid isPermaLink="false">http://www.jeffersonswheel.org/?p=198</guid>
		<description><![CDATA[Our USENIX WebApps 2011 Paper is now available: Jonathan Burket, Patrick Mutchler, Michael Weaver, Muzzammil Zaveri, and David Evans. GuardRails: A Data-Centric Web Application Security Framework. 2nd USENIX Conference on Web Application Development (WebApps 2011). Portland, Oregon, 15-16 June 2011. Abstract Modern web application frameworks have made it easy to create powerful web applications. Developing [...]]]></description>
				<content:encoded><![CDATA[<p>Our <em>USENIX WebApps</em> 2011 Paper is now available:</p>
<p>
Jonathan Burket, Patrick Mutchler, Michael Weaver, Muzzammil Zaveri, and David Evans.  <em>GuardRails: A Data-Centric Web Application Security Framework</em>.  <a href="http://www.usenix.org/event/webapps11/"><em>2nd USENIX Conference on Web Application Development</em></a> (WebApps 2011).  Portland, Oregon, 15-16 June 2011.
</p>
<p>
<center><b>Abstract</b></center><br />
Modern web application frameworks have made it easy to create powerful web applications.  Developing a secure web application, however, still requires a developer to posses a deep understanding of security vulnerabilities and attacks.  Even for experienced developers it is tedious, if not impossible, to find and eliminate all vulnerabilities.  This paper presents GuardRails, a source-to-source tool for Ruby on Rails that helps developers build secure web applications. GuardRails works by attaching security policies defined using annotations to the data model itself.  GuardRails produces a version of the input application that automatically enforces the specified policies. GuardRails helps developers prevent a myriad of security problems including cross-site scripting attacks and access control violations while providing a large degree of flexibility to support a range of policies and development styles.
</p>
<p>
<b>Full paper</b> (12 pages): [<a href="http://www.cs.virginia.edu/evans/pubs/webapps2011/guardrails-packaged.pdf">PDF</a>]<br />
<a href="http://guardrails.cs.virginia.edu/">GuardRails website</a></p>
]]></content:encoded>
			<wfw:commentRss>https://www.jeffersonswheel.org/2011/usenix-webapps-paper/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GuardRails now available!</title>
		<link>https://www.jeffersonswheel.org/2011/guardrails-now-available</link>
		<comments>https://www.jeffersonswheel.org/2011/guardrails-now-available#comments</comments>
		<pubDate>Fri, 22 Apr 2011 17:48:20 +0000</pubDate>
		<dc:creator>David Evans</dc:creator>
				<category><![CDATA[GuardRails]]></category>
		<category><![CDATA[Papers]]></category>
		<category><![CDATA[Program Analysis]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.jeffersonswheel.org/?p=184</guid>
		<description><![CDATA[The first release of the GuardRails source code is now available at https://github.com/guardrails/guardrails. GuardRails was developed by Jonathan Burket, Patrick Mutchler, Michael Weaver, and Muzzammil Zaveri. GuardRails is a web application framework that extends Ruby on Rails to provide automatic support for data-centric security policies. Developers add annotations to their data models to describe their [...]]]></description>
				<content:encoded><![CDATA[<p>The first release of the GuardRails source code is now available at <a href="https://github.com/guardrails/guardrails"><em>https://github.com/guardrails/guardrails</em></a>.  GuardRails was developed by Jonathan Burket, Patrick Mutchler, Michael Weaver, and Muzzammil Zaveri.
</p>
<p>
<a href="http://guardrails.cs.virginia.edu">GuardRails</a> is a web application framework that extends Ruby on Rails to provide automatic support for data-centric security policies.  Developers add annotations to their data models to describe their security policies, and GuardRails performs a source-to-source transformation to enforce those policies throughout the application.  There will be a paper at USENIX WebApps 2011, <em>GuardRails: A Data-Centric Web Application Security Framework</em>, available soon, that provides more details.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.jeffersonswheel.org/2011/guardrails-now-available/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
