DocumentCode :
2339065
Title :
Specification modeling and validation applied to a family of network security products
Author :
Hall, Robert J.
Author_Institution :
AT&T Res.Labs., Florham Park, NJ, USA
fYear :
2001
fDate :
26-29 Nov. 2001
Firstpage :
71
Lastpage :
80
Abstract :
A high-bandwidth, always-on Internet connection makes computers in homes and small offices attractive targets for network-based attacks. Network security gateways can protect such vulnerable hosts from attackers, but differing sets of customer needs require different feature mixes. The safest way to address this market is to provide a family of products, each member of which requires little or no end-user configuration. Since the products are closely related, the effort to validate n of them should be much less than n times the effort to validate one; however validating the correctness and security of even one such device is notoriously difficult, due to the oft-observed fact that no practical amount of testing can show the absence of security flaws. One would instead like to prove security properties, even when the products are implemented using off-the-shelf technologies that don´t lend themselves to formal reasoning. The author describes how the specification modeling and validation tools of the Interactive Specification Acquisition Tools (ISAT) suite are used to help validate members of a particular family of network security gateway products built using widely available open source technologies.
Keywords :
Internet; formal specification; internetworking; program verification; programming environments; security of data; ISAT suite; Interactive Specification Acquisition Tools; correctness; customer needs; end user configuration; feature mixes; formal reasoning; high-bandwidth always-on Internet connection; network security gateways; network security products; network-based attacks; off-the-shelf technologies; open source technologies; security flaws; security properties; specification modeling; specification modeling tools; specification validation; validation tools; Computer networks; Computer security; Home computing; IP networks; Inspection; Linux; Operating systems; Safety; Software engineering; Testing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Automated Software Engineering, 2001. (ASE 2001). Proceedings. 16th Annual International Conference on
ISSN :
1938-4300
Print_ISBN :
0-7695-1426-X
Type :
conf
DOI :
10.1109/ASE.2001.989792
Filename :
989792
Link To Document :
بازگشت