• DocumentCode
    2559497
  • Title

    Improving network system security with function extraction technology for automated calculation of program behavior

  • Author

    Pleszkoch, Mark G. ; Linger, Richard C.

  • Author_Institution
    Software Eng. Inst., Carnegie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2004
  • fDate
    5-8 Jan. 2004
  • Abstract
    Malicious attacks on systems are a threat to business, government, and defense. Many attacks exploit system behavior unknown to the developers who created it. In today´s state of art, software engineers have no practical means to determine how a sizable program will behave in all circumstances of use. This sobering reality lies at the heart of many problems in security and survivability. If full behavior is unknown, so too are embedded errors, vulnerabilities, and malicious code. This paper describes function-theoretic foundations for automated calculation of full program behavior. These foundations treat program control structures as mathematical functions or relations. The function, or behavior, of control structures can be abstracted in a stepwise process into procedure-free expressions that specify their net functional effects. Problems of computability and complexities of language semantics appear to have engineering solutions. Automated behavior calculation will add rigor to security and survivability engineering.
  • Keywords
    computer networks; program control structures; security of data; software engineering; automated behavior calculation; automated calculation; embedded errors; function extraction technology; function-theoretic foundations; language semantics; malicious attacks; malicious code; mathematical functions; mathematical relations; network system security; program behavior; program control structures; software engineers; survivability engineering; system behavior; system vulnerabilities; Art; Automatic control; Automation; Government; Heart; Humans; Open source software; Programming profession; Security; Software engineering;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System Sciences, 2004. Proceedings of the 37th Annual Hawaii International Conference on
  • Print_ISBN
    0-7695-2056-1
  • Type

    conf

  • DOI
    10.1109/HICSS.2004.1265704
  • Filename
    1265704