Analyzing security architectures

Analyzing security architectures
复制标题

分析安全架构

DOI:
--
复制
发表时间:
2010
期刊:
International Conference on Automated Software Engineering
影响因子:
--
通讯作者:
Jeffrey M. Barnes
Jeffrey M. Barnes
中科院分区:
--
文献类型:
--
作者:
Marwan Abi;Jeffrey M. Barnes

文献摘要

被引文献

相似文献

我们提出了一个半自动化的方法,SECORIA,分析安全运行时架构的安全性和一致性的面向对象的实现。类型可检查的注释描述代码中的架构意图,使静态分析能够提取一个分层对象图,该对象图完全反映所有运行时对象和它们之间的运行时关系。此外,注释可以描述模块化的代码级策略。单独的分析建立了提取的对象图和以架构描述语言记录的目标架构之间的可追溯性。最后,体系结构类型、属性和逻辑谓词描述了目标体系结构的全局约束,这些约束也将在实现中保持。我们通过分析一个3,000行的教学Java实现和安全专家设计的运行时架构来验证SECORIA方法。
We present a semi-automated approach, SECORIA, for analyzing a security runtime architecture for security and for conformance to an object-oriented implementation. Type-checkable annotations describe architectural intent within the code, enabling a static analysis to extract a hierarchical object graph that soundly reflects all runtime objects and runtime relations between them. In addition, the annotations can describe modular, code-level policies. A separate analysis establishes traceability between the extracted object graph and a target architecture documented in an architecture description language. Finally, architectural types, properties, and logic predicates describe global constraints on the target architecture, which will also hold in the implementation. We validate the SECORIA approach by analyzing a 3,000-line pedagogical Java implementation and a runtime architecture designed by a security expert.