It Is Time to Standardize Principles and Practices for Software Memory Safety.

The article addresses the subject of standardization of software memory safety, which is a critical step toward its widespread adoption across government, industry, and academia. The authors suggest that this effort necessitates a technology-neutral framework defining memory safety principles, best...

Full description

Bibliographic Details
Published in:Communications of the ACM Vol. 68; no. 2; pp. 40 - 46
Main Authors: Watson, Robert N.M., Baldwin, John, Chisnall, David, Chen, Tony, Clarke, Jessica, Davis, Brooks, Filardo, Nathaniel, Gutstein, Brett, Jenkinson, Graeme, Laurie, Ben, Mazzinghi, Alfredo, Moore, Simon, Neumann, Peter G., Okhravi, Hamed, Richardson, Alex, Rebert, Alex, Sewell, Peter, Tratt, Laurence, Vijayaraghavan, Murali, Vincent, Hugo
Format: Article
Published: Association for Computing Machinery Feb2025
Subjects:
Online Access:View this record in EBSCOhost
Description
Summary:The article addresses the subject of standardization of software memory safety, which is a critical step toward its widespread adoption across government, industry, and academia. The authors suggest that this effort necessitates a technology-neutral framework defining memory safety principles, best practices, and technical mappings to guide diverse use cases, including emerging secure IoT and cloud infrastructures. Goals include establishing tiered safety assurance levels, addressing the integration of memory-safe technologies with legacy systems, and enabling compositional reasoning about safety in heterogeneous environments. Collaboration among stakeholders—including educators, regulatory bodies, and industry leaders—is essential to create actionable guidelines that promote gradual transitions and interoperability while addressing industry concerns about cost and disruption. By defining clear standards, memory safety can evolve into a universally adopted practice, improving the security and reliability of critical systems worldwide.