Characterising user data protection of software components
Khaled M. Khan, Jingli Han, Yuliang Zheng · 2002
Proposes a scheme to characterise non-functional security properties that are embedded within the functionality of software components. The security properties may be attached to various aspects of a component, such as resource allocation, user data protection, communication, and so on. In this paper, we are particularly interested in characterising the user data protection of software components. It is often reported that software components usually suffer from security and reliability problems. It is now widely recognised that the characterisation of the security properties of software components is an important issue to boost the confidence and trust in component technology. To address this issue, the characterisation of the security properties of components is the first challenging step. The work proposed in this paper is partially based on the functional requirements defined in the Common Criteria for Information Technology Security Evaluation endorsed by NIST. The applicability of the proposed scheme is demonstrated with a simple example.