"The Language-theoretic approach (LANGSEC) regards the Internet insecurity epidemic as a consequence of ad hoc programming of input handling at all layers of network stacks, and in other kinds of software stacks." Some interesting work, although it's obviously focussing on one class of problem...

miTLS - Home

A formally verified implementation of TLS. (Being written in F# means it's a bit impractical to use as a library, though...)

Quark : A Web Browser with a Formally Verified Kernel

Building a formally-verified sandbox for browser components. Neat!

