Welcome to P K Kelkar Library, Online Public Access Catalogue (OPAC)

Normal view MARC view ISBD view

Analysis techniques for information security

Contributor(s): Datta, Anupam.
Material type: materialTypeLabelBookSeries: Synthesis digital library of engineering and computer science: ; Synthesis lectures on information security, privacy, and trust: # 2.Publisher: San Rafael, Calif. (1537 Fourth Street, San Rafael, CA 94901 USA) : Morgan & Claypool, c2010Description: 1 electronic text (ix, 152 p. : ill.) : digital file.ISBN: 9781598296303 (electronic bk.).Subject(s): Computer security -- Mathematical models | Data protection -- Mathematical modelsDDC classification: 005.8 Online resources: Abstract with links to resource Also available in print.
Contents:
Bibliography -- Authors' biographies.
5. Analyzing security protocols -- Protocol analysis methodology -- Protocol composition logic -- Modelling protocols -- Protocol logic -- Proof system -- Example -- Other protocol analysis approaches -- Recent advances -- Secure composition -- Computational soundness -- Conclusions --
A. Formalizing static analysis -- A.1. Programs -- Expressions and conditionals -- Support for nondeterminism -- Evaluation of expressions and conditional expressions -- Concrete semantics of a program -- The concrete collecting semantics of a program -- A.2. Abstraction and abstract domains -- Abstract semantics of a program -- Abstract collecting semantics -- A.3. Iterative computation -- Kleene iteration -- Widening -- Narrowing -- Chaotic iteration --
4. Analyzing security policies -- Access-matrix-based systems -- RBAC -- Security policies -- Trust management -- SPKI/SDSI -- The basic connection between SPKI/SDSI and pushdown systems -- The generalized authorization problem -- Using semirings in other kinds of authorization specifications -- Discussion -- RT --
3. Detecting buffer overruns using static analysis -- Overall tool architecture -- Codesurfer -- Constraint generation -- Taint analysis -- Constraint solving -- Detecting overruns -- Constraint resolution using linear programming -- Handling infeasible linear programs -- Implementation -- Solving constraint systems hierarchically -- Adding context sensitivity -- Summary constraints -- Experience with the tool -- WU-FTP Daemon -- Sendmail -- Performance -- Adding context sensitivity -- Effects of pointer analysis -- Shortcomings -- Related work --
2. Foundations -- Static analysis -- What is static analysis -- How is static analysis carried out -- Dataflow analysis, pushdown systems, and weighted pushdown systems -- Interprocedural dataflow analysis -- Pushdown systems -- Boolean programs -- Weighted pushdown systems -- Datalog --
1. Introduction --
Abstract: Increasingly our critical infrastructures are reliant on computers. We see examples of such infrastructures in several domains, including medical, power, telecommunications, and finance. Although automation has advantages, increased reliance on computers exposes our critical infrastructures to a wider variety and higher likelihood of accidental failures and malicious attacks. Disruption of services caused by such undesired events can have catastrophic effects, such as disruption of essential services and huge financial losses. The increased reliance of critical services on our cyberinfrastructure and the dire consequences of security breaches have highlighted the importance of information security. Authorization, security protocols, and software security are three central areas in security in which there have been significant advances in developing systematic foundations and analysis methods that work for practical systems. This book provides an introduction to this work, covering representative approaches, illustrated by examples, and providing pointers to additional work in the area.
    average rating: 0.0 (0 votes)
Item type Current location Call number Status Date due Barcode Item holds
E books E books PK Kelkar Library, IIT Kanpur
Available EBKE341
Total holds: 0

Mode of access: World Wide Web.

System requirements: Adobe Acrobat Reader.

Part of: Synthesis digital library of engineering and computer science.

Series from website.

Includes bibliographical references (p. 133-149).

Bibliography -- Authors' biographies.

5. Analyzing security protocols -- Protocol analysis methodology -- Protocol composition logic -- Modelling protocols -- Protocol logic -- Proof system -- Example -- Other protocol analysis approaches -- Recent advances -- Secure composition -- Computational soundness -- Conclusions --

A. Formalizing static analysis -- A.1. Programs -- Expressions and conditionals -- Support for nondeterminism -- Evaluation of expressions and conditional expressions -- Concrete semantics of a program -- The concrete collecting semantics of a program -- A.2. Abstraction and abstract domains -- Abstract semantics of a program -- Abstract collecting semantics -- A.3. Iterative computation -- Kleene iteration -- Widening -- Narrowing -- Chaotic iteration --

4. Analyzing security policies -- Access-matrix-based systems -- RBAC -- Security policies -- Trust management -- SPKI/SDSI -- The basic connection between SPKI/SDSI and pushdown systems -- The generalized authorization problem -- Using semirings in other kinds of authorization specifications -- Discussion -- RT --

3. Detecting buffer overruns using static analysis -- Overall tool architecture -- Codesurfer -- Constraint generation -- Taint analysis -- Constraint solving -- Detecting overruns -- Constraint resolution using linear programming -- Handling infeasible linear programs -- Implementation -- Solving constraint systems hierarchically -- Adding context sensitivity -- Summary constraints -- Experience with the tool -- WU-FTP Daemon -- Sendmail -- Performance -- Adding context sensitivity -- Effects of pointer analysis -- Shortcomings -- Related work --

2. Foundations -- Static analysis -- What is static analysis -- How is static analysis carried out -- Dataflow analysis, pushdown systems, and weighted pushdown systems -- Interprocedural dataflow analysis -- Pushdown systems -- Boolean programs -- Weighted pushdown systems -- Datalog --

1. Introduction --

Abstract freely available; full-text restricted to subscribers or individual document purchasers.

Google book search

INSPEC

Google scholar

Compendex

Increasingly our critical infrastructures are reliant on computers. We see examples of such infrastructures in several domains, including medical, power, telecommunications, and finance. Although automation has advantages, increased reliance on computers exposes our critical infrastructures to a wider variety and higher likelihood of accidental failures and malicious attacks. Disruption of services caused by such undesired events can have catastrophic effects, such as disruption of essential services and huge financial losses. The increased reliance of critical services on our cyberinfrastructure and the dire consequences of security breaches have highlighted the importance of information security. Authorization, security protocols, and software security are three central areas in security in which there have been significant advances in developing systematic foundations and analysis methods that work for practical systems. This book provides an introduction to this work, covering representative approaches, illustrated by examples, and providing pointers to additional work in the area.

Also available in print.

Title from PDF t.p. (viewed on April 30, 2010).

There are no comments for this item.

Log in to your account to post a comment.

Powered by Koha