DocumentCode :
2898551
Title :
A Logical Framework of Proof-Carrying Survivability
Author :
Zuo, Yanjun ; Lande, Suhas
Author_Institution :
Univ. of North Dakota, Grand Forks, ND, USA
fYear :
2011
fDate :
16-18 Nov. 2011
Firstpage :
472
Lastpage :
481
Abstract :
Users often need to acquire external software systems or link other software components to their existing systems. It is crucial that those software objects are trustworthy and will not compromise the survivability of the existing systems, particularly for those systems used to support mission-critical services in national defense, healthcare, and financial services. This paper presents a logical framework for proof-carrying survivability: (1) a system user publishes their survivability requirement policy for the system in which they are interested, (2) a system provider collects verification evidence from third-party evaluators, formulates survivability compliance, and compiles a proof to show that their system satisfies the user´s requirements, and finally, (3) the system user verifies that the proof is valid. If so, the system can be safely acquired or linked without sacrificing the survivability of the existing system. We specify an application specific logic to facilitate proof compliance and verification. We implemented the framework to show that the proof can be generated automatically by a prover program and verified mechanically in real time by a trustworthy checker program.
Keywords :
object-oriented programming; program verification; security of data; theorem proving; external software systems; logical framework; mission-critical services; proof compliance; proof verification; proof-carrying survivability; prover program; software components; survivability compliance; survivability requirement policy; third-party evaluators; trustworthy checker program; verification evidence; Fault tolerance; Fault tolerant systems; Monitoring; Principal component analysis; Security; Semantics; Servers; Survivability; analysis; logic; proof; trust;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2011 IEEE 10th International Conference on
Conference_Location :
Changsha
Print_ISBN :
978-1-4577-2135-9
Type :
conf
DOI :
10.1109/TrustCom.2011.61
Filename :
6120854
Link To Document :
بازگشت