【24h】

TINMAN: A Resource Bound Security Checking System for Mobile Code

机译:TINMAN:用于移动代码的资源绑定安全检查系统

获取原文
获取原文并翻译 | 示例

摘要

Resource security pertains to the prevention of unauthorized usage of system resources that may not directly cause corruption or leakage of information. A common breach of resource security is the class of attacks called DoS (Denial of Service) attacks. This paper proposes an architecture called TINMAN whose goal is to efficiently and effectively safeguard resource security for mobile source code written in C. We couple resource usage checks at the programming language level and at the run-time system level. This is achieved by the generation of a resource skeleton from source code. This resource skeleton abstracts the resource consumption behavior of the program which is validated by means of a resource usage certificate that is derived from proof generation. TINMAN uses resource-usage checking tools to generate proof obligations required of the resource usage certificate and provides full coverage by monitoring any essential property not guaranteed by the certificates. We shall describe the architecture of TINMAN and give some experimental results of the preliminary TINMAN implementation.
机译:资源安全性涉及防止未经授权使用系统资源,而这些资源可能不会直接导致信息损坏或泄漏。一种常见的破坏资源安全性的攻击类型是DoS(拒绝服务)攻击。本文提出了一种名为TINMAN的体系结构,其目标是有效地保护用C编写的移动源代码的资源安全性。我们在编程语言级别和运行时系统级别上对资源使用情况检查进行耦合。这是通过从源代码生成资源框架来实现的。此资源框架抽象了程序的资源消耗行为,该行为通过从证明生成派生的资源使用证书进行了验证。 TINMAN使用资源使用检查工具来生成资源使用证书所需的证明义务,并通过监视证书未保证的任何基本属性来提供全面覆盖。我们将描述TINMAN的体系结构,并给出初步TINMAN实施的一些实验结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号