首页> 外文会议>International Conference on Software Engineering >Building high assurance secure applications using security patterns for capability-based platforms
【24h】

Building high assurance secure applications using security patterns for capability-based platforms

机译:使用基于功能的平台的安全模式来构建高度安全的安全应用

获取原文

摘要

Building high assurance secure applications requires the proper use of security mechanisms and assurances provided by the underlying secure platform. However, applications are often built using security patterns and best practices that are agnostic with respect to the intricate specifics of the different underlying platforms. This independence from the underlying platform leaves a gap between security patterns and underlying secure platforms. In this PhD research abstract, we propose a novel approach to bridge this gap. Specifically, we propose reusable capability-specific design fragments for security patterns, which are specialization for patterns in a capability-based system. The focus is on systems that adhere to a capability-based security model, which we consider as the underlying platforms, to provide desired application-wide security properties. We also discuss assumptions and levels of assurance for these reusable designs and their use in the verification of application designs.
机译:构建高保证安全应用程序需要正确使用安全机制和底层安全平台提供的保证。但是,通常使用安全模式和最佳实践来构建应用程序,而这些安全模式和最佳实践与不同底层平台的复杂细节无关。与底层平台的这种独立性在安全模式和底层安全平台之间留下了空白。在本博士研究摘要中,我们提出了一种弥合这一差距的新颖方法。具体来说,我们为安全模式提出了可重用的,针对特定能力的设计片段,这些片段是针对基于能力的系统中的模式的专用化。重点是遵循基于功能的安全模型的系统,我们将其视为基础平台,以提供所需的应用程序范围的安全属性。我们还将讨论这些可重用设计的假设和保证级别,以及它们在应用程序设计的验证中的使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号