首页> 外文会议>IEEE International Conference on Software Architecture >Flaws in Flows: Unveiling Design Flaws via Information Flow Analysis
【24h】

Flaws in Flows: Unveiling Design Flaws via Information Flow Analysis

机译:流中的缺陷:通过信息流分析揭示设计缺陷

获取原文

摘要

This paper presents a practical and formal approach to analyze security-centric information flow policies at the level of the design model. Specifically, we focus on data confidentiality and data integrity objectives. In its guiding principles, the approach is meant to be amenable for designers (e.g., software architects) that have very limited or no background in formal models, logics, and the like. To this aim, we provide an intuitive graphical notation, which is based on the familiar Data Flow Diagrams, and which requires as little effort as possible in terms of extra security-centric information the designer has to provide. The result of the analysis algorithm is the early discovery of design flaws in the form of violations of the intended security properties. The approach is implemented as a publicly available plugin for Eclipse and evaluated with four real-world case studies from publicly available literature.
机译:本文提出了一种实用和形式化的方法来在设计模型级别分析以安全性为中心的信息流策略。具体来说,我们专注于数据机密性和数据完整性目标。在其指导原则中,该方法适用于在正式模型,逻辑等方面具有非常有限的背景或没有背景的设计人员(例如,软件设计师)。为此,我们提供了直观的图形表示法,该表示法以熟悉的数据流程图为基础,并且在设计人员必须提供的额外的以安全性为中心的信息方面,它需要尽可能少的精力。分析算法的结果是早期发现设计缺陷,其形式是违反预期的安全属性。该方法是作为Eclipse的公共可用插件实现的,并根据来自公共可用文献的四个实际案例研究进行了评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号