首页> 外文期刊>Computers & Security >An Aspect-oriented Approach For The Systematicrnsecurity Hardening Of Code
【24h】

An Aspect-oriented Approach For The Systematicrnsecurity Hardening Of Code

机译:一种面向方面的代码系统安全性强化方法

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we present an aspect-oriented approach for the systematic security hardening of source code. It aims at allowing developers to perform software security hardening by providing an abstraction over the actions required to improve the security of the program. This is done by giving them the capabilities to specify high-level security hardening plans that leverage a priori defined security hardening patterns. These patterns describe the required steps and actions to harden security code, including detailed information on how and where to inject the security code. We show the viability and relevance of our approach by: (1) elaborating security hardening patterns and plans to common security hardening practices, (2) realizing these patterns by implementing them into aspect-oriented languages, (3) applying them to secure applications, (4) testing the hardened applications. Furthermore, we discuss, in this paper, our insights on the appropriateness, strengths and limitations of the aspect-oriented paradigm for security hardening.
机译:在本文中,我们提出了一种面向方面的方法,用于对源代码进行系统的安全加固。它旨在通过提供对提高程序安全性所需的动作的抽象,允许开发人员执行软件安全性强化。通过为他们提供指定高级安全性强化计划的能力,可以利用先验定义的安全性强化模式。这些模式描述了强化安全代码所需的步骤和操作,包括有关如何以及在何处注入安全代码的详细信息。我们通过以下方式展示了该方法的可行性和相关性:(1)详细阐述安全加固模式和计划以适用于常见的安全加固实践;(2)通过将其实施为面向方面的语言来实现这些模式;(3)将其应用于安全应用程序; (4)测试硬化的应用程序。此外,我们在本文中讨论了对面向方面的安全强化范式的适当性,优势和局限性的见解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号