首页> 外文会议>Frontiers of engineering >Unifying Disparate Tools in Software Security
【24h】

Unifying Disparate Tools in Software Security

机译:统一软件安全中的不同工具

获取原文
获取原文并翻译 | 示例

摘要

How much can you trust software? When you install a piece of code, such as a video game or a device driver for a new camera, how can you be sure the code won't delete all of your files or install a key-stroke logger that captures your passwords? How can you ensure that the software doesn't contain coding bugs or logic errors that might leave a security hole?rnTraditional approaches to software security have assumed that users could easily determine when they were installing code and whether or not software was trustworthy in a particular context. This assumption was reasonable when computers controlled few things of real value, when only a small number of people (typically experts) installed software, and when the software itself was relatively small and simple. But the security landscape has changed drastically with advances in technology (e.g., the explosive growth of the Internet, the increasing size and complexity of software) and new business practices (e.g., outsourcing and the development of open-source architecture). Furthermore, the more we rely on software to control critical systems, from phones and airplanes to banks and armies, the more desperately we need mechanisms to ensure that software is truly trustworthy.
机译:您可以信任软件多少?当您安装一段代码(例如,视频游戏或新相机的设备驱动程序)时,如何确定该代码不会删除您的所有文件,也不会安装捕获您密码的按键记录器?您如何确保软件不包含可能导致安全漏洞的编码错误或逻辑错误?rn传统的软件安全方法假定用户可以轻松确定何时安装代码以及在特定情况下软件是否值得信赖。上下文。当计算机控制的是很少有实际价值的东西,只有少数人(通常是专家)安装软件,并且软件本身相对较小且简单时,这种假设是合理的。但是,随着技术的进步(例如,互联网的爆炸性增长,软件的规模和复杂性的增加)和新的业务实践(例如,外包和开放源代码体系结构的发展),安全领域已发生了巨大变化。此外,我们越依赖软件来控制关键系统,从电话,飞机到银行和军队,我们迫切需要确保软件真正值得信赖的机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号