DocumentCode
2898551
Title
A Logical Framework of Proof-Carrying Survivability
Author
Zuo, Yanjun ; Lande, Suhas
Author_Institution
Univ. of North Dakota, Grand Forks, ND, USA
fYear
2011
fDate
16-18 Nov. 2011
Firstpage
472
Lastpage
481
Abstract
Users often need to acquire external software systems or link other software components to their existing systems. It is crucial that those software objects are trustworthy and will not compromise the survivability of the existing systems, particularly for those systems used to support mission-critical services in national defense, healthcare, and financial services. This paper presents a logical framework for proof-carrying survivability: (1) a system user publishes their survivability requirement policy for the system in which they are interested, (2) a system provider collects verification evidence from third-party evaluators, formulates survivability compliance, and compiles a proof to show that their system satisfies the user´s requirements, and finally, (3) the system user verifies that the proof is valid. If so, the system can be safely acquired or linked without sacrificing the survivability of the existing system. We specify an application specific logic to facilitate proof compliance and verification. We implemented the framework to show that the proof can be generated automatically by a prover program and verified mechanically in real time by a trustworthy checker program.
Keywords
object-oriented programming; program verification; security of data; theorem proving; external software systems; logical framework; mission-critical services; proof compliance; proof verification; proof-carrying survivability; prover program; software components; survivability compliance; survivability requirement policy; third-party evaluators; trustworthy checker program; verification evidence; Fault tolerance; Fault tolerant systems; Monitoring; Principal component analysis; Security; Semantics; Servers; Survivability; analysis; logic; proof; trust;
fLanguage
English
Publisher
ieee
Conference_Titel
Trust, Security and Privacy in Computing and Communications (TrustCom), 2011 IEEE 10th International Conference on
Conference_Location
Changsha
Print_ISBN
978-1-4577-2135-9
Type
conf
DOI
10.1109/TrustCom.2011.61
Filename
6120854
Link To Document