A framework for an active interface to characterise compositional security contracts of software components

A framework for an active interface to characterise compositional security contracts of software components
复制标题

DOI:
10.1109/aswec.2001.948505
复制
发表时间:
2001-08
期刊:
Proceedings 2001 Australian Software Engineering Conference
影响因子:
--
通讯作者:
K. Khan;Jun Han;Yuliang Zheng
K. Khan;Jun Han;Yuliang Zheng
中科院分区:
其他
文献类型:
--
作者:
K. Khan;Jun Han;Yuliang Zheng

文献摘要

被引文献

相似文献

本文提出了一个基于原子组件所暴露的安全属性构建组合安全契约(CsC)的框架。该框架利用组件的接口结构来确定软件组件的组合安全契约。活动接口为组件提供了一个推理和评估组件是否适合满足特定应用的某些安全要求的基础。基于从组件接口获取的安全信息,活动接口能够推断候选组件是否满足设想的全系统应用的安全要求。在实际组合发生之前,参与组件可以识别组件之间的任何安全不匹配或差异。暴露软件组件的安全属性可以作为组件之间信任关系的基础,并且所暴露的安全性可能会影响封闭系统的底层安全性。
This paper presents a framework for constructing compositional security contracts (CsC) based on the security property exposed by the atomic component. The framework uses interface structure of components in order to determine the CsC of software components. An active interface provides the component a basis for reasoning and assessing a component's suitability to meet certain security requirements of a particular application. Based on the security information available from the component interface, an active interface can reason whether the candidate component meets the security requirements for an envisaged systemwide application. Any security mismatches or discrepancies between components can be identified by the participating components before an actual composition takes place. Exposing the security properties of software components can be the basis for a trust relationship among components, and the exposed security could affect the underlying security of the enclosing system.