Towards Automatic Integration Of Or-BAC Security Policies Using Aspects - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

Towards Automatic Integration Of Or-BAC Security Policies Using Aspects

Résumé

We propose a formal method to automatically integrate security rules regarding an access control policy (expressed in Or-BAC) in Java programs. Given an untrusted application and a set of Or-BAC security rules, our method derives corresponding AspectJ aspects. Derived aspects modify the behaviour of the underlying program so as to meet the policy. Then, these aspects are weaved into the target program (using the AspectJ compiler). The result is a trusted program on which the security policy is enforced. This approach was applied in order to secure the behaviour of a travel agency application.
Fichier principal
Vignette du fichier
sigproc-sp.pdf (86.06 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00525490 , version 1 (12-10-2010)

Identifiants

  • HAL Id : hal-00525490 , version 1

Citer

Yliès Falcone, Mohamad Jaber. Towards Automatic Integration Of Or-BAC Security Policies Using Aspects. International Conference on Software Engineering Research and Practice (SERP 2010), Jul 2010, Las Vegas, Nevada, United States. pp.5. ⟨hal-00525490⟩
161 Consultations
66 Téléchargements

Partager

Gmail Facebook X LinkedIn More