Swinburne
Browse

A framework for an active interface to characterise compositional security contracts of software components

Download (909.2 kB)
conference contribution
posted on 2024-07-13, 07:01 authored by Khaled M. Khan, Jun HanJun Han, Yuliang Zhang
This paper presents a framework for constructing compositional security contracts (CsC) based on the security property exposed by the atomic component. The framework uses interface structure of components in order to determine the CsC of software components. An active interface provides the component a basis for reasoning and assessing a component's suitability to meet certain security requirements of a particular application. Based on the security information available from the component interface, an active interface can reason whether the candidate component meets the security requirements for an envisaged systemwide application. Any security mismatches or discrepancies between components can be identified by the participating components before an actual composition takes place. Exposing the security properties of software components can be the basis for a trust relationship among components, and the exposed security could affect the underlying security of the enclosing system.

History

Available versions

PDF (Published version)

ISBN

9780769512549

Journal title

13th Australian Software Engineering Conference, Canberra, Australia, 27-28 August 2001 / Douglas D. Grant and Leon Sterling (eds.)

Conference name

13th Australian Software Engineering Conference, Canberra, Australia, 27-28 August 2001 / Douglas D. Grant and Leon Sterling eds.

Issue

1

Pagination

9 pp

Publisher

IEEE

Copyright statement

Copyright © 2001 IEEE. The published version is reproduced in accordance with the copyright policy of the publisher. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.

Language

eng

Usage metrics

    Publications

    Categories

    No categories selected

    Keywords

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC