【24h】

On Probabilistic Application Compliance

机译:关于概率应用程序合规性

获取原文

摘要

The Security-by-Contract is a paradigm developed to offer a secure environment in which mobile applications can be executed by respecting the security policies of interest. Especially in the Android Apps marketplace, establishing precisely the expected secure app behavior is typically a complex operation that is prone to approximations. Hence, it is worth considering extensions of purely functional approaches that allow the security relevant actions to be quantitatively assessed. This also opens the possibility to balance the application of (expensive) enforcement mechanisms with the security guarantees. With these objectives in view, in this paper we define a probabilistic extension of the Security-by-Contract model, and we show its impact in real-world scenarios through the analysis of several practical Android applications.
机译:逐合的安全性是为提供安全环境而开发的范例,其中可以通过尊重感兴趣的安全策略来执行移动应用程序。 特别是在Android应用市场中,正是建立预期的安全应用程序行为通常是一个复杂的操作,易于近似。 因此,值得考虑允许定量评估安全相关行动的纯粹功能方法的延伸。 这也开辟了平衡(昂贵的)执法机制与安全保证的可能性。 通过这些目标,鉴于这些目标,在本文中,我们定义了通过合同模型的概率扩展,并通过分析了几种实际的Android应用程序来显示其对现实情景的影响。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号