arrow
Return

Security enforcement aware software development

delete2009-07-01
delete5
delete
OA
AI
D
Dries Vanoverberghe *
F
Frank Piessens
DOI:10.1016/j.infsof.2008.01.009delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
In the domain of security policy enforcement, the concerns of application developers are almost completely ignored. As a consequence, it is hard to develop useful and reliable applications that will function properly under a variety of policies. This paper addresses this issue for application security policies specified as security automata, and enforced through run-time monitoring. Our solution consists of three elements: the definition of an abstract interface to the policy that is being enforced, a sound construct to query that policy, and a static verification algorithm that guarantees absence of security policy violations in critical blocks of code. (C) 2008 Elsevier B.V. All rights reserved.
Keywords:
Security automata
Run-time enforcement
Inline reference monitor
Static verification
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Information and Software Technology cover
Information and Software Technology
IF:
4.3
Papers:
3.7K
Citations:
7.7K

Organization

K
KU Leuven
Scholars:
5.7W
Papers: 5.2W
Citations: 8.1W