See this document in CiteSeerX!

An Approach for Certifying Security in Software Components  (Make Corrections)  
Anup K. Ghosh, Gary McGraw
Proc. 21st NIST-NCSC National Information Systems Security Conference



  Home/Search   Context   Related

 
View or download:
rstcorp.com/pub/papers/cert.ps
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  rstcorp.com/papers/chrono1998 (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: The growth of Internet-based electronic commerce, with its potential to create new business markets and streamline corporate operations, has been hindered over the past three years by concerns over the security of the system. While several secure transaction protocols have emerged to allay concerns, most security violations in practice are made possible by flaws in e-commerce client/server software. The approach outlined in this paper develops a certification process for testing software... (Update)

Similar documents (at the sentence level):
71.4%:   An Approach for Certifying Security in Software Components - Ghosh, McGraw (1998)   (Correct)

Active bibliography (related documents):   More   All
0.8:   Towards Analyzing Security-Critical Software During.. - Ghosh, McGraw, Charron.. (1996)   (Correct)
0.6:   An Automated Approach for Identifying Potential.. - Ghosh, O'Connor, McGraw (1998)   (Correct)
0.5:   An Approach for Analyzing the Robustness of Windows NT Software - Ghosh, Shah, Schmid (1998)   (Correct)

Similar documents based on text:   More   All
0.6:   ITS4: A Static Vulnerability Scanner for C and C++ Code - Viega, Bloch, Kohno, McGraw (2000)   (Correct)
0.3:   CyberCash Credit Card Protocol Version 0.8 - Eastlake, Boesch, Crocker, Yesil (1996)   (Correct)
0.3:   Certifying E-Commerce Software for Security - Ghosh (1999)   (Correct)

BibTeX entry:   (Update)

@inproceedings{ ghosh98approach,
    author = "A. K. Ghosh and G. McGraw",
    title = "An Approach for Certifying Security in Software Components",
    booktitle = "Proc. 21st {NIST}-{NCSC} National Information Systems Security Conference",
    pages = "42--48",
    year = "1998",
    url = "citeseer.ist.psu.edu/104720.html" }
Citations (may not include all citations):
60   Firewalls and Internet Security (context) - Cheswick, Bellovin - 1994
46   The cops security checker system - Farmer, Spafford - 1990
20   Improving the security of your site by breaking into it (context) - Farmer, Venema - 1993
17   An automated approach for identifying potential vulnerabilit.. - Ghosh, O'Connor et al. - 1998
11   Property-based testing: A new approach to testing for assura.. - Fink, Bishop - 1997
10   The TAMU security package: An ongoing response to Internet i.. - Safford, Schales et al. - 1993
7   Confidently assessing a zero probability of software failure (context) - Voas, Michael et al. - 1995
6   Predicting how badly (context) - Voas, Charron et al. - 1997
3   Available by ftp from ftp://ftp (context) - Klaus, scanner - 1995
3   Predicting software 's minimum-time-to-hazard and mean-timet.. - Voas, Miller - 1995
3   Communications of the ACM (context) - Schneier, security et al. - 1997
3   Gluing together software components: How good is your glue (context) - Voas, McGraw et al. - 1996

Documents on the same site (http://rstcorp.com/papers/chrono-1998.html):   More
COTS Software Failures: Can Anything be Done? - Voas, Payne   (Correct)
Agent Trustworthiness - Kassab, Voas (1998)   (Correct)
Automated Software Test Data Generation for Complex Programs - Michael, McGraw (1998)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC