An Approach for Certifying Security in Software Components

A. K. Ghosh, Gary E. McGraw · 1998

The growth of Internet-based electronic commerce, with its potential to create new business markets and streamline corporate operations, has been hindered over the past three years by concerns over the security of the system. While several secure transaction protocols have emerged to allay concerns, most security violations in practice are made possible by flaws in e-commerce client/server software. The approach outlined in this paper develops a certification process for testing software components for security properties. The anticipated results from this research is a process and set of core white-box and black-box testing technologies to certify the security of software components. The manifestation of the product is a stamp of approval in the form of a digital signature. 1 Introduction Component-based Internet technologies such as Java and ActiveX are making the use of software components easier and more pervasive than ever before. Today, the Internet is being harnessed by main-s...

Read the paper · More papers on PaperTik