Abstract: This paper introduces a panel discussion on establishing assurance evidence that mobile code applications perform as expected by the user, without the side effects that have been demonstrated as possible in constructed examples of malicious or "rogue" applets. The paper's principal authors, Schaefer and Pinsky, have been engaged in cooperative research with the JavaSoft community to gain understanding of the complexities of assurance for mobile code applications. The paper discusses part of this on-going research. The panel adds the voices and experience of a continuing researcher, Dean, and of active practitioners from the principal vendors of mobile-code-enabled (and enabling) products. The panel actively debates the issues of providing compelling assurance evidence relating to the control of such code.
Index Terms:
software portability; mobile computing assurance; mobile code applications; malicious applets; rogue applets; JavaSoft; research; vendors; software portability; Java; data security
Citation:
M. Schaefer, S. Pinsky, D. Dean, Li Gong, J. Roskind, B. Fox, "Ensuring assurance in mobile computing," sp, pp.0114, 1997 IEEE Symposium on Security and Privacy, 1997