Download presentation
Presentation is loading. Please wait.
Published bySimon Stokes Modified over 9 years ago
1
Towards Higher Assurance Software Construction via Aspects Thomas Llansó, Inventor
2
Background Software is ever more complex –Determining correctness very challenging What about software security functions? –Are they correct and properly integrated? –Often we hire independent labs to find out Employ an evaluation process (e.g., “Common Criteria”) Can be slow and costly (>6 months, >$100k)
3
Roots of the Problem Painful Integration –Security code… cuts across systems mixed in with application code hard to evolve over time –Integration via non-specialists Painful Evaluation –Manual, slow tracing –Extra scrutiny due to pedigree –Repeat as system evolves
4
What we want 1.improved security 2.easier integration What if we had a tool that could... –Automatically integrate security code –Enforce separation of duties –Allow automated tracing 3. faster evaluations 4. lower costs …even as software changes over time? requirements ↔ security code ↔ application code
5
Underlying Technology Key technologies/techniques in tool –Requirements Taxonomy –Aspects (from Aspect-Oriented programming) –Marker Annotations –XML for mappings / representation
6
Tool (“SRTD”)
7
Technology Applications Many stakeholders may find use for the tool StakeholderApplication Security DevelopersBuild and map security code Application DevelopersVerify mapping correctness Test PersonnelVerify code meets requirements System EvaluatorsRequirements ↔ Code tracing
8
Commercial Opportunities For technical information contact: Thomas Llanso, Inventor 443-778-6343 thomas.llanso@jhuapl.edu For licensing information contact: Norma Lee Todd, Technology Manager Office of Technology Transfer The Johns Hopkins University Applied Physics Laboratory 11100 Johns Hopkins Road Laurel, MD 20723 443-778-4528 norma.todd@jhuapl.edu www.jhuapl.edu/ott
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.