Tracking dependent information flows

Zhioua, Zeineb; Roudier, Yves; Ameur Boulifa, Rabéa; Kechiche, Takoua; Short, Stuart
ICISSP 2017, 3rd International Conference on Information Systems Security and Privacy, February 19-21, 2017, Porto, Portugal

Ensuring the compliance of developed software with security requirements is a challenging task due to imprecision on the security guidelines definition, and to the lack of automatic and formal means to lead this verification. In this paper, we present our approach that aims at integrating the formal specification and verification of security guidelines in early stages of the development life cycle by combining the model checking
together with information flow analysis. We formally specify security guidelines that involve dependent information flows as a basis to lead formal verification through model checking, and provide precise feedback to the developer.

DOI
Type:
Conférence
City:
Porto
Date:
2017-02-19
Department:
Sécurité numérique
Eurecom Ref:
5207
Copyright:
© Insticc. Personal use of this material is permitted. The definitive version of this paper was published in ICISSP 2017, 3rd International Conference on Information Systems Security and Privacy, February 19-21, 2017, Porto, Portugal and is available at : http://dx.doi.org/10.5220/0006209301790189
See also:

PERMALINK : https://www.eurecom.fr/publication/5207