DocumentCode
2371641
Title
High-assurance synthesis of security services from basic microservices
Author
Kim, Sung ; Bastani, Farokh B. ; Yen, I-Ling ; Chen, Ing-Ray
Author_Institution
Dept. of Comput. Sci., Texas Univ., Richardson, TX, USA
fYear
2003
fDate
17-20 Nov. 2003
Firstpage
154
Lastpage
165
Abstract
Computer systems are vulnerable to many different types of threats ranging from harmless mistakes in data entries to malicious attacks by computer hackers. Furthermore, the explosive growth of the Internet has introduced very sophisticated ways of compromising any computer system. Consequently, a great deal of time and effort has been spent on achieving computer network security. Most of the efforts to deal with computer security have emphasized the network security aspect (i.e., the focus so far has been on intruders from outside the system). However, there also exists a significant threat from "enemies within", e.g. attacks due to malicious code embedded in the software. Whether it is intentional or not, there are many software bugs that can potentially be the source of the information misusages. One approach for dealing with this issue is to certify component security and deduce system security from its components. The advantage of this method is that it is much simpler to validate a small component as compared with a large monolithic software system. In this paper, we define a general process that allows the system security to be decomposed into orthogonal aspects so that it is possible to rigorously certify the security of a system. The approach is illustrated for the security service for an e-mail application.
Keywords
Internet; certification; electronic mail; formal verification; object-oriented programming; security of data; Internet; component security certification; computer hackers; computer network security; computer systems; computer threats; e-mail application; information misusage; malicious attacks; malicious code embedding; microservices; monolithic software system; security service synthesis; software bugs; system security; Computer bugs; Computer hacking; Computer networks; Computer security; Data security; Embedded software; Explosives; Information security; Internet; Software systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Reliability Engineering, 2003. ISSRE 2003. 14th International Symposium on
ISSN
1071-9458
Print_ISBN
0-7695-2007-3
Type
conf
DOI
10.1109/ISSRE.2003.1251039
Filename
1251039
Link To Document