• DocumentCode
    2198524
  • Title

    Integrating a flexible modeling framework (FMF) with the network security assessment instrument to reduce software security risk

  • Author

    Gilliam, David P. ; Powell, John D.

  • Author_Institution
    Jet Propulsion Lab., California Inst. of Technol., Pasadena, CA, USA
  • fYear
    2002
  • fDate
    2002
  • Firstpage
    153
  • Lastpage
    158
  • Abstract
    The network security assessment instrument is a comprehensive set of tools that can be used individually or collectively to ensure the security of network aware software applications and systems. Using the various tools collectively provide a distinct advantage for assuring the security of software and systems. Each tool´s resulting output provides feedback into the other tools. Thus, more comprehensive assessment results are attained through the leverage each tool provides to the other when they are employed in concert. Previous portions of this work were presented at the IEEE Wet Ice 2000 and 2001 Workshops and are printed in those proceedings. This paper presents a portion of an overall research project on the generation of the network security assessment instrument to aid developers in assessing and assuring the security of software in the development and maintenance lifecycles. This portion, the flexible modeling framework (FMF), focuses on modeling requirements and early lifecycle designs to discover vulnerabilities that result from interaction between system components that are either under development in a new system or proposed as additions to an existing system. There are early indications that this new approach, the flexible modeling framework (FMF), has promise in the areas of network security as well as other critical areas such as system safety. Information about the overall research effort regarding network security is available at http://security.jpl.nasa.gov/rssr.
  • Keywords
    computer networks; formal verification; security of data; development lifecycles; early lifecycle designs; flexible modeling framework; maintenance lifecycles; network aware software; network security assessment instrument; requirements; software security risk reduction; system safety; vulnerabilities; Application software; Conferences; Ice; Information security; Instruments; Output feedback; Safety; Software maintenance; Software systems; Software tools;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Enabling Technologies: Infrastructure for Collaborative Enterprises, 2002. WET ICE 2002. Proceedings. Eleventh IEEE International Workshops on
  • ISSN
    1080-1383
  • Print_ISBN
    0-7695-1748-X
  • Type

    conf

  • DOI
    10.1109/ENABL.2002.1030002
  • Filename
    1030002