loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
14th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprise (WETICE'05)
Application of Lightweight Formal Methods to Software Security
Linkoping, Sweden
June 13-June 15
ISBN: 0-7695-2362-5
David P. Gilliam, California Institute of Technology
John D. Powell, California Institute of Technology
Matt Bishop, University of California at Davis
Formal specification and verification of security has proven a challenging task. There is no single method that has proven feasible. Instead, an integrated approach which combines several formal techniques can increase the confidence in the verification of software security properties. Such an approach which specifies security properties in a library that can be re-used by 2 instruments and their methodologies developed for the National Aeronautics and Space Administration (NASA) at the Jet Propulsion Laboratory (JPL) are described herein The Flexible Modeling Framework (FMF) is a model based verification instrument that uses Promela and the SPIN model checker. The Property Based Tester (PBT) uses TASPEC and a Test Execution Monitor (TEM). They are used to reduce vulnerabilities and unwanted exposures in software during the development and maintenance life cycles. These instruments are currently being piloted with a COTS Server-Agent Application.
Citation:
David P. Gilliam, John D. Powell, Matt Bishop, "Application of Lightweight Formal Methods to Software Security," wetice, pp.160-165, 14th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprise (WETICE'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.