2009 16th Asia-Pacific Software Engineering Conference 2009
DOI: 10.1109/apsec.2009.52
|View full text |Cite
|
Sign up to set email alerts
|

A Formal Framework to Integrate Timed Security Rules within a TEFSM-Based System Specification

Abstract: Formal methods are very useful in software industry and are becoming of paramount importance in practical engineering techniques. They involve the design and the modeling of various system aspects expressed usually through different paradigms. In this paper, we propose to combine two modeling formalisms in order to express both functional and security timed requirements of a system. First, the system behavior is specified based on its functional requirements using TEFSM (Timed Extended Finite State Machine) fo… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2

Citation Types

0
2
0

Year Published

2010
2010
2015
2015

Publication Types

Select...
2
2
1

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(2 citation statements)
references
References 12 publications
0
2
0
Order By: Relevance
“…Mallouli et al also proposed, in Mallouli et al (2008), a passive testing method which analyzes SOAP messages with XML sniffers to check whether a system respects a policy. In Mallouli et al (2009), a security testing method is described to test systems with timed security rules modelled with Nomad. The specification is augmented by means of specific algorithms for basic prohibition and obligation rules only.…”
Section: Web Services Security Overviewmentioning
confidence: 99%
See 1 more Smart Citation
“…Mallouli et al also proposed, in Mallouli et al (2008), a passive testing method which analyzes SOAP messages with XML sniffers to check whether a system respects a policy. In Mallouli et al (2009), a security testing method is described to test systems with timed security rules modelled with Nomad. The specification is augmented by means of specific algorithms for basic prohibition and obligation rules only.…”
Section: Web Services Security Overviewmentioning
confidence: 99%
“…Our first motivation comes from the paper Mallouli et al (2009) which describes a testing method from Nomad rules. This one can handle basic rules composed of abstract actions only and can be applied on generic systems.…”
Section: Web Services Security Overviewmentioning
confidence: 99%