.

A High-level Aspect-oriented-based Framework for Software Security Hardening

LAUR Repository

Show simple item record

dc.contributor.author Mourad, Azzam
dc.contributor.author Laverdiere, Marc-André
dc.contributor.author Debbabi, Mourad
dc.date.accessioned 2015-11-25T12:25:29Z
dc.date.available 2015-11-25T12:25:29Z
dc.date.copyright 2008
dc.date.issued 2015-11-25
dc.identifier.issn 1939-3555 en_US
dc.identifier.uri http://hdl.handle.net/10725/2689
dc.description.abstract In this paper, we present an aspect-oriented approach and propose a high-level language called SHL (Security Hardening Language) for the systematic security hardening of software. The primary contribution of this proposition is providing the software architects with the capabilities to perform security hardening by applying well-defined solutions and without the need to have expertise in the security solution domain. At the same time, the security hardening is applied in an organized and systematic way in order not to alter the original functionalities of the software. This is done by providing an abstraction over the actions required to improve the security of a program and adopting aspect-oriented programming to build and develop the solutions. SHL allows the developers to describe and specify the security hardening plans and patterns needed to harden systematically security into open source software. It is a minimalist language built on top of the current aspect-oriented technologies that are based on advice-poincut model and can also be used in conjunction with them. We explore the viability and relevance of our proposition by applying it into several security hardening case studies and presenting their experimental results. en_US
dc.language.iso en en_US
dc.title A High-level Aspect-oriented-based Framework for Software Security Hardening en_US
dc.type Article en_US
dc.description.version Published en_US
dc.author.school SAS en_US
dc.author.idnumber 200904853 en_US
dc.author.woa N/A en_US
dc.author.department Computer Science and Mathematics en_US
dc.description.embargo N/A en_US
dc.relation.journal Information Security Journal: A Global Perspective en_US
dc.journal.volume 17 en_US
dc.journal.issue 2 en_US
dc.article.pages 56-74 en_US
dc.identifier.doi http://dx.doi.org/10.1080/19393550801911230 en_US
dc.identifier.ctation Mourad, A., Laverdière, M. A., & Debbabi, M. (2008). A high-level aspect-oriented-based framework for software security hardening. Information Security Journal: A Global Perspective, 17(2), 56-74. en_US
dc.author.email azzam.mourad@lau.edu.lb
dc.identifier.url http://www.tandfonline.com/doi/abs/10.1080/19393550801911230
dc.orcid.id https://orcid.org/0000-0001-9434-5322


Files in this item

Files Size Format View

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record

Search LAUR


Advanced Search

Browse

My Account