It Is Time to Standardize Principles and Practices for Software Memory Safety.

The article addresses the subject of standardization of software memory safety, which is a critical step toward its widespread adoption across government, industry, and academia. The authors suggest that this effort necessitates a technology-neutral framework defining memory safety principles, best...

Full description

Bibliographic Details
Published in:Communications of the ACM Vol. 68; no. 2; pp. 40 - 46
Main Authors: Watson, Robert N.M., Baldwin, John, Chisnall, David, Chen, Tony, Clarke, Jessica, Davis, Brooks, Filardo, Nathaniel, Gutstein, Brett, Jenkinson, Graeme, Laurie, Ben, Mazzinghi, Alfredo, Moore, Simon, Neumann, Peter G., Okhravi, Hamed, Richardson, Alex, Rebert, Alex, Sewell, Peter, Tratt, Laurence, Vijayaraghavan, Murali, Vincent, Hugo
Format: Article
Published: Association for Computing Machinery Feb2025
Subjects:
Online Access:View this record in EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=182365569&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 182365569
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Feb2025
      vid: 68
      iid: 2
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        182365569
        10.1145/3708553
      ppf: 40
      ppct: 6
      formats:
      tig:
        atl: It Is Time to Standardize Principles and Practices for Software Memory Safety.
      aug:
        au:
          Watson, Robert N.M.
          Baldwin, John
          Chisnall, David
          Chen, Tony
          Clarke, Jessica
          Davis, Brooks
          Filardo, Nathaniel
          Gutstein, Brett
          Jenkinson, Graeme
          Laurie, Ben
          Mazzinghi, Alfredo
          Moore, Simon
          Neumann, Peter G.
          Okhravi, Hamed
          Richardson, Alex
          Rebert, Alex
          Sewell, Peter
          Tratt, Laurence
          Vijayaraghavan, Murali
          Vincent, Hugo
        affil:
          University of Cambridge, Cambridge, United Kingdom
          Ararat River Consulting, Ashland, VA, USA
          Microsoft, Seattle, WA, USA
          Cambridge University, Cambridge, United Kingdom
          SRI International, Menlo Park, CA, USA
          Capabilities Limited, Cambridge, United Kingdom
          Google, Mountain View, CA, USA
          MIT, Lincoln Laboratory, Cambridge, MA, USA
          King College London, London, United Kingdom
          Arm Limited, Cambridge, USA
      su:
        Computer software
        Computer storage devices
        Computer security software
        Standardization
        Safety
        Best practices
      sug:
        subj:
          Computer software
          Computer storage devices
          Computer security software
          Standardization
          Safety
          Best practices
      ab: The article addresses the subject of standardization of software memory safety, which is a critical step toward its widespread adoption across government, industry, and academia. The authors suggest that this effort necessitates a technology-neutral framework defining memory safety principles, best practices, and technical mappings to guide diverse use cases, including emerging secure IoT and cloud infrastructures. Goals include establishing tiered safety assurance levels, addressing the integration of memory-safe technologies with legacy systems, and enabling compositional reasoning about safety in heterogeneous environments. Collaboration among stakeholders—including educators, regulatory bodies, and industry leaders—is essential to create actionable guidelines that promote gradual transitions and interoperability while addressing industry concerns about cost and disruption. By defining clear standards, memory safety can evolve into a universally adopted practice, improving the security and reliability of critical systems worldwide.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2025
    holdings:
      @attributes:
        islocal: N