Integrating Contract-based Security Monitors in the Software Development Life Cycle - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2008

Integrating Contract-based Security Monitors in the Software Development Life Cycle

Résumé

Software systems, containing security vulnerabilities, continue to be created and released to consumers. We need to adopt improved software engineering practices to reduce the security vulnerabilities in modern systems. These practices should begin with stated security policies and end with systems which are quantitatively, not just qualitatively, more secure. Currently, contracts have been proposed for reliability and formal verification; yet, their use in security is limited. In this work, we propose a contract-based security assertion monitoring framework (CB SAMF) that is intended to reduce the number of security vulnerabilities that are exploitable, spanning multiple software layers, to be used in an enhanced systems development life cycle (SDLC).
Fichier principal
Vignette du fichier
FLACOS-FULL.pdf (137.17 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

inria-00546624 , version 1 (28-06-2021)

Identifiants

  • HAL Id : inria-00546624 , version 1

Citer

Alexander M. Hoole, Isabelle Simplot-Ryl, Issa Traoré. Integrating Contract-based Security Monitors in the Software Development Life Cycle. FLACOS 2008 - 2nd Workshop on Formal Languages and Analysis of Contract-Oriented Software, Nov 2008, Malta, Malta. ⟨inria-00546624⟩
73 Consultations
19 Téléchargements

Partager

Gmail Facebook X LinkedIn More