Formal Specification and Verification of Security Guidelines
Zeineb Zhioua, Yves Roudier, Rabea Boulifa Ameur · 2017
Ensuring the compliance of developed software with general and application-specific security requirements is a challenging task due to the lack of automatic and formal means to lead this verification. In this paper, we present our approach that aims at integrating the formal specification and verification of security guidelines in early stages of the development lifecycle by combining the model checking together with information flow analysis. We present our framework that is based on an extension of LTS (Labeled Transition Systems) by data dependence information to cover the end-to-end specification and verification of security guidelines.