Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Experience report: How to extract security protocols’ specifications from C libraries
Vazquez Sandoval, Itzel; Lenzini, Gabriele
2018In 2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC), Volume 2
Peer reviewed
 

Files


Full Text
11307.pdf
Author postprint (267.64 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Security protocol specifications; formal manalysis; C reverse engineering
Abstract :
[en] Often, analysts have to face a challenging situation when formally verifying the implementation of a security protocol: they need to build a model of the protocol from only poorly or not documented code, and with little or no help from the developers to better understand it. Security protocols implementations frequently use services provided by libraries coded in the C programming language; automatic tools for codelevel reverse engineering offer good support to comprehend the behavior of code in object-oriented languages but are ineffective to deal with libraries in C. Here we propose a systematic, yet human-dependent approach, which combines the capabilities of state-of-the-art tools in order to help the analyst to retrieve, step by step, the security protocol specifications from a library in C. Those specifications can then be used to create the formal model needed to carry out the analysis.
Disciplines :
Computer science
Author, co-author :
Vazquez Sandoval, Itzel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Lenzini, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
External co-authors :
no
Language :
English
Title :
Experience report: How to extract security protocols’ specifications from C libraries
Publication date :
June 2018
Event name :
COMPSAC 2018: 42nd IEEE International Conference on Computers, Software and Applications
Event organizer :
IEEE
Event date :
23-27 July 2018
Audience :
International
Main work title :
2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC), Volume 2
Publisher :
IEEE
ISBN/EAN :
978-1-5386-2666-5
Pages :
719-724
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Available on ORBilu :
since 01 August 2018

Statistics


Number of views
148 (30 by Unilu)
Number of downloads
233 (12 by Unilu)

Scopus citations®
 
1
Scopus citations®
without self-citations
0

Bibliography


Similar publications



Contact ORBilu