A Process Framework for Characterising Security Properties of Component-Based Software Systems

  • Authors:
  • Khaled M. Khan;Jun Han

  • Affiliations:
  • -;-

  • Venue:
  • ASWEC '04 Proceedings of the 2004 Australian Software Engineering Conference
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents a security characterisation processframework for software components and their compositionsin order to address the issue of trust in component basedsoftware. The process is based on the idea of publishingtrust related properties of software components in machinereadable as well as understandable form at the componentlevel and incorporating such properties with runtime compositionof the application system. We explore the actualprocess involved in specifying publishable security propertiesof atomic components, component certification, reasoningabout compositional security contracts, and characterisingultimate systems-level security properties to inspiretrust in software components.