首页> 外文会议>International Workshop on Formal Aspects in Security and Trust >Reflections on Trust: Trust Assurance by Dynamic Discovery of Static Properties
【24h】

Reflections on Trust: Trust Assurance by Dynamic Discovery of Static Properties

机译:关于信任的思考:通过动态发现静态属性信任保证

获取原文

摘要

Static analyses allow dangerous code to be rejected before it runs. The distinct security concerns of code providers and end users necessitate that analysis be performed, or at least confirmed, during deployment rather than development; examples of this approach include bytecode verification and proof-carrying code. The situation is more complex in multi-party distributed systems, in which the multiple web services deploying code may have their own competing interests. Applying static analysis techniques to such systems requires the ability to identify the codebase running at a remote location and to dynamically determine the static properties of a codebase associated with an identity. In this paper, we provide formal foundations for these requirements. Rather than craft special-purpose combinatory to address these specific concerns, we define a reflective, higher-order applied pi calculus and apply it. We treat process abstractions as serialized program files, and thus permit the direct observation of process syntax. This leads to a semantics quite different from that of higher-order pi or applied pi.
机译:静态分析允许在运行之前拒绝危险的代码。代码提供商和最终用户的不同安全问题需要在部署而不是开发期间进行分析或至少确认;该方法的示例包括字节码验证和牵引代码。多方分布式系统中的情况更复杂,其中多个Web服务部署代码可能具有自己的竞争利益。将静态分析技术应用于此类系统需要能够识别在远程位置处运行的代码库,并动态地确定与身份相关联的码字的静态属性。在本文中,我们为这些要求提供正式基础。无论是如何解决这些特定问题的,而不是工艺专用组合,我们定义了反光,高阶施加的PI微积分并应用它。我们将流程抽象视为序列化程序文件,从而允许直接观察过程语法。这导致了与高阶PI或应用PI完全不同的语义。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号