Analyzing security architectures
Analyzing security architectures
复制标题
分析安全架构
DOI:
--
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
Jeffrey M. Barnes
中科院分区:
文献类型:
--
作者:
Marwan Abi;Jeffrey M. Barnes
We present a semi-automated approach, SECORIA, for analyzing a security runtime architecture for security and for conformance to an object-oriented implementation. Type-checkable annotations describe architectural intent within the code, enabling a static analysis to extract a hierarchical object graph that soundly reflects all runtime objects and runtime relations between them. In addition, the annotations can describe modular, code-level policies. A separate analysis establishes traceability between the extracted object graph and a target architecture documented in an architecture description language. Finally, architectural types, properties, and logic predicates describe global constraints on the target architecture, which will also hold in the implementation. We validate the SECORIA approach by analyzing a 3,000-line pedagogical Java implementation and a runtime architecture designed by a security expert.