A Method for Certifying Code in Trust-By-Policy-Adherence
نویسندگان
چکیده
This paper proposes and details the notion of trust by policy adherence (TBPA), meaning that code can be certified on the basis of its security-related behaviors rather than its origins and integrity. We describe the overall life cycle of code in this setting, and propose a detailed method whereby a program’s policy adherence can be verified. We suggest enforcing security policies over code by means of aspect-oriented programming (AOP). Based on the characteristics of AOP programs, we model security policies and a verification process using alternating temporal logic. This method can be used to verify whether a given program complies with a wide range of security policies, including both safety and liveness policies. It can also verify whether the original program is affected by policy execution. We argue that TBPA provides a suitable semantic framework for certifying code, and represents a step forward from trusted code toward trustworthy code.
منابع مشابه
A survey of the effective factors in students’ adherence to university dress code policy, using the theory of reasoned action
Introduction: Recognizing the determinants of behavior plays amajor role in identification and application of effective strategiesfor encouraging individuals to follow the intended pattern ofbehavior. The present study aimed to analyze the universitystudents’ behaviors regarding the amenability to dress code, usingthe theory of reasoned action (TRA).Methods: In this cross sectional study, 472 s...
متن کاملTowards Compiler-Independent Certifying Compilation
Certifying compilation allows a compiler to produce annotations which prove that target code abides by a speciied safety policy. An independent veriier can check the code without needing to trust the compiler. For such a system to be generally useful, the safety policy should be expressive enough to allow diierent compilers to eeectively produce certiiable code. In this work, we use our experie...
متن کاملCertification Support for Automatically Generated Programs
Although autocoding techniques promise large gains in software development productivity, their “real-world” application has been limited, particularly in safety-critical domains. Often, the major impediment is the missing trustworthiness of these systems: demonstrating—let alone formally certifying—the trustworthiness of automatic code generators is extremely difficult due to their complexity a...
متن کاملEstimating VAT Policy and Compliance Gap across the Iran’s Provinces
Abstract This paper aims to propose a method for measuring the value added tax gap decomposed into two main components: compliance and policy gaps. By definition, policy gap is the difference between the potential tax revenue and what can be collected according to tax code. In comparison, the compliance gap is defined as the difference between full compliance with tax code and the actual compl...
متن کاملInvestigation of Students\' Attitudes toward Professional Dress Code and the Level of Adherence to This Code at Kerman University of Medical Sciences, Kerman, Iran
Background and Objectives: The attitudes to the professional dress code as well as the level of adherence to this code are of utmost importance in clinical settings. This study aimed to investigate the students' attitudes and adherence regarding the professional dress code at Kerman University of Medical Sciences, Kerman, Iran. Methods: This descriptive analytical study was conducted on 368 st...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- JCP
دوره 6 شماره
صفحات -
تاریخ انتشار 2011