• DocumentCode
    2864955
  • Title

    Component-Based Malicious Software Engineer Intrusion Detection

  • Author

    Shin, Michael E. ; Sethia, Snehadeep ; Patel, Nipul

  • Author_Institution
    Dept. of Comput. Sci., Texas Tech Univ., Lubbock, TX, USA
  • fYear
    2011
  • fDate
    27-29 June 2011
  • Firstpage
    21
  • Lastpage
    30
  • Abstract
    These days, security-sensitive business application systems are developed and maintained by more than one software engineer, some of which may be unethical or malicious. Unethical software engineers can insert malicious code to the systems or maliciously change the existing code in the systems to gain personal benefits. As the result, security of the business application systems can be compromised. This paper describes an approach to detecting malicious code created by malicious software engineers in components. This paper is an extension to our previous work detecting malicious code attacking security-sensitive information within a component. In particular, this paper focuses on detecting malicious code in a component that intrudes security-sensitive information in different components in an application. For this, an application system monitor(s) is designed to detect intrusion between components using the business process encapsulated in the monitor(s). The proposed approach is applied to the ATM system and B2B electronic commerce system to evaluate the performance.
  • Keywords
    automatic teller machines; electronic commerce; object-oriented programming; security of data; ATM system; B2B electronic commerce system; component-based malicious software engineer intrusion detection; malicious code detection; security-sensitive business application systems; security-sensitive information; Asynchronous transfer mode; Detectors; Intrusion detection; Maintenance engineering; Servers; Software; application; component; detection; intrusion; malicious software engineer;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Secure Software Integration and Reliability Improvement (SSIRI), 2011 Fifth International Conference on
  • Conference_Location
    Jeju Island
  • Print_ISBN
    978-1-4577-0780-3
  • Electronic_ISBN
    978-0-7695-4453-3
  • Type

    conf

  • DOI
    10.1109/SSIRI.2011.33
  • Filename
    5992000