kirancodes.me
To Proof Maintenance & Beyond!

Tools for model-based security engineering

Jan Jürjens, Jorge Fox

Abstract

We present tool-support for checking UML models and C code against security requirements. A framework supports implementing verification routines, based on XMI output of the diagrams from UML CASE tools, and on control flow generated from the C code. The tool also supports weaving security aspects into the code generated from the models. Advanced users can use this open-source framework to implement verification routines for the constraints of self-defined security requirements. We focus on a verification routine that automatically verifies crypto-based software for security requirements by using automated theorem provers.

BibTeX
@inproceedings{Juerjens-Fox:ICSE06,
  author    = {Jan J{\"{u}}rjens and
               Jorge Fox},
  title     = {Tools for model-based security engineering},
  booktitle = {ICSE},
  pages     = {819--822},
  publisher = {{ACM}},
  year      = {2006},
}

Related papers