DocumentCode :
2573947
Title :
An integrated security model for component-based systems
Author :
Nissanke, Nimal
Author_Institution :
London South Bank Univ., London
fYear :
2007
fDate :
25-28 Sept. 2007
Firstpage :
638
Lastpage :
645
Abstract :
Maliciously planted code in third-party components, as well as coding errors, design flaws and functional failures that could be subverted by malicious attackers, expose component-based systems (CBS) to potentially serious security threats. Approaches to securing CBSs fall basically into two categories: execution of untrusted components in a secure environment and secure composition of components at the design stage. Taking the former approach, this research uses logical separation instead of the physical separation. Works addressing security in this manner are limited and tend to focus on assuring security from the operating systems perspective, or the perspective of a single security objective. The latter is a limitation, particularly in modern industrial applications requiring the assurance of more than one security objective within the same application at the same time. In this respect, this paper presents an integrated multi-objective component security (ICS) model comprising Bell-LaPadula and Biba security models, for preventing security breaches in confidentiality and integrity in CBS.
Keywords :
operating systems (computers); security of data; Bell-LaPadula security model; Biba security model; coding errors; component-based systems; design flaws; functional failures; integrated multi-objective component security model; logical separation; maliciously planted code; operating systems; third-party components; Automation; Computer industry; Economies of scale; Embedded computing; Humans; Information security; Information systems; Operating systems; Programming; Robustness; Bell-LaPadula security model; Biba security model; Component-based systems; component security; multi-objective security modelling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Emerging Technologies and Factory Automation, 2007. ETFA. IEEE Conference on
Conference_Location :
Patras
Print_ISBN :
978-1-4244-0825-2
Electronic_ISBN :
978-1-4244-0826-9
Type :
conf
DOI :
10.1109/EFTA.2007.4416829
Filename :
4416829
Link To Document :
بازگشت