Passer à la navigation principale Passer à la recherche Passer au contenu principal

Slicing for security of code

  • LIST-DTSI-SLA CEA

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

8 Citations (Scopus)

Résumé

Bugs in programs implementing security features can be catastrophic: for example they may be exploited by malign users to gain access to sensitive data. These exploits break the confidentiality of information. All security analyses assume that softwares implementing security features correctly implement the security policy, i.e. are security bug-free. This assumption is almost always wrong and IT security administrators consider that any software that has no security patches on a regular basis should be replaced as soon as possible. As programs implementing security features are usually large, manual auditing is very error prone and testing techniques are very expensive. This article proposes to reduce the code that has to be audited by applying a program reduction technique called slicing. Slicing transforms a source code into an equivalent one according to a set of criteria. We show that existing slicing criteria do not preserve the confidentiality of information. We introduce a new automatic and correct source-to-source method properly preserving the confidentiality of information i.e. confidentiality is guaranteed to be exactly the same in the original program and in the sliced program.

langue originaleAnglais
titreTrusted Computing - Challenges and Applications - First International Conference on Trusted Computing and Trust in Information Technologies, TRUST 2008, Proceedings
Pages133-142
Nombre de pages10
Les DOIs
étatPublié - 27 oct. 2008
Modification externeOui
Evénement1st International Conference on Trusted Computing and Trust in Information Technologies, TRUST 2008 - Villach, Autriche
Durée: 11 mars 200812 mars 2008

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume4968 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence1st International Conference on Trusted Computing and Trust in Information Technologies, TRUST 2008
Pays/TerritoireAutriche
La villeVillach
période11/03/0812/03/08

Empreinte digitale

Examiner les sujets de recherche de « Slicing for security of code ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation