Engineering PapersSearch

NASA NTRS · 20060043597

Using software security analysis to verify the secure socket layer (SSL) protocol

Abstract

nal Aeronautics and Space Administration (NASA) have tens of thousands of networked computer systems and applications. Software Security vulnerabilities present risks such as lost or corrupted data, information the3, and unavailability of critical systems. These risks represent potentially enormous costs to NASA. The NASA Code Q research initiative 'Reducing Software Security Risk (RSSR) Trough an Integrated Approach '' offers, among its capabilities, formal verification of software security properties, through the use of model based verification (MBV) to address software security risks. [1,2,3,4,5,6] MBV is a formal approach to software assurance that combines analysis of software, via abstract models, with technology, such as model checkers, that provide automation of the mechanical portions of the analysis process. This paper will discuss: The need for formal analysis to assure software systems with respect to software and why testing alone cannot provide it. The means by which MBV with a Flexible Modeling Framework (FMF) accomplishes the necessary analysis task. An example of FMF style MBV in the verification of properties over the Secure Socket Layer (SSL) communication protocol as a demonstration.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Powell, John D.. 2004-06-14. Using software security analysis to verify the secure socket layer (SSL) protocol. https://ntrs.nasa.gov/citations/20060043597

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related reports

Advocating for Equality of Contribution: The Research Software Engineer (RSE)

Heliophysics depends on RSEs to properly engineer software. However, RSEs receive unequal treatment compared to their science counterparts, resulting in unsustainable talent loss. These restrictions include lack of credit for their contributions and insufficient training. This paper describes what a RSE is and proposes solutions, including implementing appropriate recognition standards.

software

Control System Software Development: Fall 2020 Internship Final Report

The Launch Control System (LCS) is an integral part of the Space Launch System (SLS) as it responds and sends instructions to both the vehicle and ground systems. This semester, the focus has been on the development of assurance tests for the Graphical User Interface (GUI) software components of the LCS. This will help ensure that the system software functions as intended. This paper describes the goals, procedures, and results of this process as well as lessons learned that may be useful for future interns working on similar projects.

software

Ask-the-expert: Active Learning Based Knowledge Discovery Using the Expert

Often the manual review of large data sets, either for purposes of labeling unlabeled instances or for classifying meaningful results from uninteresting (but statistically significant) ones is extremely resource intensive, especially in terms of subject matter expert (SME) time. Use of active learning has been shown to diminish this review time significantly. However, since active learning is an iterative process of learning a classifier based on a small number of SME-provided labels at each iteration, the lack of an enabling tool can hinder the process of adoption of these technologies in real-life, in spite of their labor-saving potential. In this demo we present ASK-the-Expert, an interactive tool that allows SMEs to review instances from a data set and provide labels within a single framework. ASK-the-Expert is powered by an active learning algorithm for training a classifier in the backend. We demonstrate this system in the context of an aviation safety application, but the tool can be adopted to work as a simple review and labeling tool as well, without the use of active learning.

software