Enforcing mobile application security through probabilistic contracts
Contributo in Atti di convegno
Data di Pubblicazione:
2014
Abstract:
Security for mobile devices is a problem of capital importance, especially due to new threats coming from malicious applications. Though several security solutions have already been proposed, security requirements have been always considered as binary: Allow or deny. We argue that a more realistic vision of security can be given using probabilistic and quantitative requirements. In this paper, we introduce a probabilistic description of the behavior of an application that a user is going to execute. We also allow the definition of finer grained user security requirements, by introducing probabilistic clause modifiers. Later, we present a probabilistic version of the Security-by-Contract framework to guarantee probabilistic security requirements.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
Contract-based Security approaches; Probabilistic Contr; Probabilistic policy compliance; Run-time enforcement.
Elenco autori:
Sgandurra, Daniele; Saracino, Andrea; Martinelli, Fabio; Matteucci, Ilaria
Link alla scheda completa:
Pubblicato in: