loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Sixth International Conference on Quality Software (QSIC'06)
PORTAM: Policy, Requirements and Threats Analyzer for Mobile Code Application
Beijing, China
October 27-October 28
ISBN: 0-7695-2718-3
Haruhiko Kaiya, Shinshu University, Japan
Kouta Sasaki, Shinshu University, Japan
Kenji Kaijiri, Shinshu University, Japan
Users and providers of an information system should clearly understand the threats caused by the system as well as clarify the requirements for the system before they use the system. Especially, they should be very careful when they use a system with components and/or services provided by third parties. However, there are few methods or tools to learn and confirm such issues. In this paper, we present a supporting tool called "PORTAM" for such users and providers to understand the threats and the requirements. Suppose some requirements cannot be satisfied when some threats are avoided, and vice versa. In such cases, they should decide whether the requirements should be satisfied or the threats should be avoided. The tool also helps them to decide such kinds of trade-offs. Current version of this tool handles Java mobile code applications, thus users of our tool can easily feel real threats. Although the current version deals only with Java components, the ideas behind the tool can be applied to software in general. We finally report experimental results to confirm the usefulness and the educational effects of this tool.
Citation:
Haruhiko Kaiya, Kouta Sasaki, Kenji Kaijiri, "PORTAM: Policy, Requirements and Threats Analyzer for Mobile Code Application," qsic, pp.125-132, Sixth International Conference on Quality Software (QSIC'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.