Title :
An integrated security model for component-based systems
Author_Institution :
London South Bank Univ., London
Abstract :
Maliciously planted code in third-party components, as well as coding errors, design flaws and functional failures that could be subverted by malicious attackers, expose component-based systems (CBS) to potentially serious security threats. Approaches to securing CBSs fall basically into two categories: execution of untrusted components in a secure environment and secure composition of components at the design stage. Taking the former approach, this research uses logical separation instead of the physical separation. Works addressing security in this manner are limited and tend to focus on assuring security from the operating systems perspective, or the perspective of a single security objective. The latter is a limitation, particularly in modern industrial applications requiring the assurance of more than one security objective within the same application at the same time. In this respect, this paper presents an integrated multi-objective component security (ICS) model comprising Bell-LaPadula and Biba security models, for preventing security breaches in confidentiality and integrity in CBS.
Keywords :
operating systems (computers); security of data; Bell-LaPadula security model; Biba security model; coding errors; component-based systems; design flaws; functional failures; integrated multi-objective component security model; logical separation; maliciously planted code; operating systems; third-party components; Automation; Computer industry; Economies of scale; Embedded computing; Humans; Information security; Information systems; Operating systems; Programming; Robustness; Bell-LaPadula security model; Biba security model; Component-based systems; component security; multi-objective security modelling;
Conference_Titel :
Emerging Technologies and Factory Automation, 2007. ETFA. IEEE Conference on
Conference_Location :
Patras
Print_ISBN :
978-1-4244-0825-2
Electronic_ISBN :
978-1-4244-0826-9
DOI :
10.1109/EFTA.2007.4416829