• DocumentCode
    2753613
  • Title

    Applying the Layered Decision Model to the Design of Language-Based Security Systems

  • Author

    Wei, Huaqiang ; Alves-Foss, Jim

  • Author_Institution
    Dept. of Comput. Sci., Idaho Univ., Moscow, ID
  • fYear
    2006
  • fDate
    16-18 Sept. 2006
  • Firstpage
    182
  • Lastpage
    187
  • Abstract
    Safeguarding practices for networked systems involves decisions in at least three areas: identification of well-defined security policies, selection of cost-effective defense strategies, and implementation of real-time defense tactics. These practices also apply to the language-based defense mechanism for a software system, which is a subset of a networked security system. Although much research has been conducted to develop language-based defense mechanisms to improve the security of software systems, the most comprehensive requirement is still the enforcement of security policies through the end-to-end control mechanism. However, the security enforcement cannot be easily achieved without a comprehensive decision model that integrates decisions about security policies, cost-effective defense strategies, and real-time defense tactics into a single, efficient framework to guide security experts in designing, developing and deploying language-based defense mechanisms in a software system. To address these problems this paper first reviews progress in language-based security defense and the layered decision modeling (LDM) technique. It then explores how to apply the LDM in the design of cost-effective language-based defense mechanisms for software systems through a sample analysis
  • Keywords
    cost-benefit analysis; security of data; cost-benefit analysis; end-to-end control; language-based security systems; layered decision modeling; networked system; software system security; Computer security; Cost benefit analysis; Data security; Information security; Inspection; Intrusion detection; Memory management; Protection; Real time systems; Software systems; Language-based security; case study; cost-benefit analysis; layered decision model;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Reuse and Integration, 2006 IEEE International Conference on
  • Conference_Location
    Waikoloa Village, HI
  • Print_ISBN
    0-7803-9788-6
  • Type

    conf

  • DOI
    10.1109/IRI.2006.252410
  • Filename
    4018487