首页> 外文会议> >Mitigating Security Risks in Systems that Support Pervasive Services and Computing: Access-Driven Verification, Validation and Testing
【24h】

Mitigating Security Risks in Systems that Support Pervasive Services and Computing: Access-Driven Verification, Validation and Testing

机译:减轻支持普适服务和计算的系统中的安全风险:访问驱动的验证,验证和测试

获取原文

摘要

Unique operational and environmental characteristics define pervasive services and computing; they, too, define an ideal atmosphere in which security risks flourish. Ever-present accessibility through the networked and wireless infrastructures, dependency on autonomous and often anonymous computing agents, and the ubiquitous nature of pervasive services make them both enticing and easy targets for ill-intentioned activities. To help mitigate that risk, we propose an adaptive, access-driven verification, validation and testing (VV&T) strategy that, through a Process/Object Model of Computation, (a) identifies those resources and software objects most susceptible to attack, (b) enumerates violable constraints and assumptions underlying those attacks, and (c) provides multi-level strategies incorporating resources, software objects, and constraints and assumptions to determine if, and to what extent, systems supporting pervasive computing are vulnerable to security exploits. The VV&T strategies are defined to accommodate various levels of access to the software development process and its artifacts.
机译:独特的运营和环境特征定义了无处不在的服务和计算;它们也定义了一种理想的气氛,在这种气氛中安全风险不断增加。通过网络和无线基础设施的无处不在的访问性,对自治和通常是匿名计算代理的依赖以及普适服务的无处不在的性质,使它们既是诱人的又是容易进行恶意活动的目标。为了帮助减轻这种风险,我们提出了一种自适应的,访问驱动的验证,确认和测试(VV&T)策略,该策略通过计算的流程/对象模型来(a)识别最容易受到攻击的资源和软件对象,(b )列举了这些攻击所依据的可违反的约束条件和假设,并且(c)提供了包含资源,软件对象以及约束条件和假设的多级策略,以确定支持普适计算的系统是否容易受到安全漏洞的攻击以及在多大程度上受到安全漏洞的攻击。定义了VV&T策略,以适应对软件开发过程及其工件的各种访问级别。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号