A Quantified Model of Security Policies, with an Application for Injection-Attack Prevention