Run-Time Security Evaluation (RTSE) for Distributed Applications
Cristina Şerban, Bruce McMillin · 1996
Formal security specifications for a distributed application can be checked for compliance at run-time using executable security assertions. We propose the RunTime Security Evaluation (RTSE) method which makes use of histories/traces of events, assertions and operational evaluation in the distributed environment to ensure the security specifications for the application are fulfilled at run-time. A model problem is used to aid in developing the security requirements formally. 1. Introduction Traditionally, security models have provided checks that the security policy is strictly adhered to at design and implementation times. A formal security policy is given, a design is proposed, then formal proofs must be supplied that the verification of design guarantees enforcement of the security policy. When the implementation is constructed, formal proofs are used again for verification to show a priori that the system or application resulting from that implementation will comply to the formal ...