【24h】

Security-oriented program transformations

机译:面向安全的程序转换

获取原文

摘要

Security experts generally believe that, "security cannot be added on, it must be designed from the beginning" [1]. This is because the typical way of improving system security by patches is ad hoc and has not produced good results. My work shows that retrofitting security does not need to be a massive reengineering effort, nor does it need to be ad hoc. Security solutions can be added through systematic, general purpose security-oriented program transformations. I have been maintaining a catalog of security-oriented program transformations; so far the catalog contains forty two transformations. These transformations improve the traditional approaches of security engineering and keep software secure in the face of new security threats.
机译:安全专家通常认为,“不能增加安全性,必须从一开始就对其进行设计” [1]。这是因为通过修补程序提高系统安全性的典型方法是临时性的,并且未产生良好的效果。我的工作表明,对安全性进行改造无需进行大量的重新设计工作,也不必是临时性的。可以通过系统的,通用的,面向安全性的程序转换来添加安全性解决方案。我一直在维护面向安全的程序转换的目录。到目前为止,目录包含42个转换。这些转变改进了安全工程的传统方法,并在面对新的安全威胁时保持软件的安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号