Integrated Security Verification and Validation: Case Study
Dorina Ghindici, Gilles Grimaud, Isabelle Simplot-Ryl, Yanguo Liu, Issa Traoré · Conference on Local Computer Networks · 2006
In most current approaches to software security, security flaws are fixed only after they have been exploited. To increase user confidence in software products, the software industry needs more proactive and durable security solutions by addressing security requirements throughout the software system lifecycle, including requirements and design specification, testing, and maintenance phases. Appropriate security analysis techniques must be used for each of these phases. In this paper, we illustrate an integrated security analysis framework, which combines a quantitative design security analysis technique, with a static program analyzer, which tracks unsafe information flows. We illustrate the framework by presenting a case study based on medical information card