首页> 外文会议>International Conference on Software Engineering >Building high assurance secure applications using security patterns for capability-based platforms
【24h】

Building high assurance secure applications using security patterns for capability-based platforms

机译:使用基于能力的平台的安全模式构建高保证安全应用程序

获取原文

摘要

Building high assurance secure applications requires the proper use of security mechanisms and assurances provided by the underlying secure platform. However, applications are often built using security patterns and best practices that are agnostic with respect to the intricate specifics of the different underlying platforms. This independence from the underlying platform leaves a gap between security patterns and underlying secure platforms. In this PhD research abstract, we propose a novel approach to bridge this gap. Specifically, we propose reusable capability-specific design fragments for security patterns, which are specialization for patterns in a capability-based system. The focus is on systems that adhere to a capability-based security model, which we consider as the underlying platforms, to provide desired application-wide security properties. We also discuss assumptions and levels of assurance for these reusable designs and their use in the verification of application designs.
机译:建立高保证安全应用需要正确使用底层安全平台提供的安全机制和保证。但是,应用程序通常是使用安全模式和最佳实践构建,这些实践是关于不同底层平台的复杂细节而不可知的。这种来自底层平台的独立性在安全模式和底层安全平台之间留下了差距。在这项博士学位的研究中,我们提出了一种弥合这一差距的新方法。具体地,我们为安全模式提出了可重复使用的能力特定的设计片段,这是基于能力的系统中的模式的专业化。重点是在系统上遵循基于能力的安全模型,我们认为是底层平台,以提供所需的应用程序范围的安全性。我们还讨论了这些可重复使用的设计的假设和保证水平及其在验证应用程序设计中的使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号