Powerpoint

SAS '04

Click to download
Reviews
Shared by: 44aff241486ce297
Categories
Tags
Stats
views:
17
rating:
not rated
reviews:
0
posted:
6/5/2009
language:
English
pages:
0
SAS ‘04 Reducing Software Security Risk through an Integrated Approach David P. Gilliam and John D. Powell 1 Acknowledgement  NOTE:    This research was carried out at the Jet Propulsion Laboratory, California Institute of Technology, under a contract with the National Aeronautics and Space Administration The work was sponsored by the NASA Office of Safety and Mission Assurance under the Software Assurance Research Program lead by the NASA Software IV&V Facility This activity is managed locally at JPL through the Assurance and Technology Program Office 2 Current Collaborators      David Gilliam – Principle Investigator, JPL John Powell – JPL Software Engineer Matt Bishop – Associate Professor of Computer Science, University of California at Davis Eric Haugh – UC Davis Researcher http://rssr.jpl.nasa.gov 3 Goal  Reduce security risk to the computing environment by mitigating vulnerabilities in the software development and maintenance life cycles Provide an instrument and tools to help avoid vulnerabilities and exposures in software To aid in complying with security requirements and best practices   4 Problem    Lack of Experts: Brooks – “No Silver Bullet” is still valid (IEEE Software Engineering, 1987) Poor Security Requirements Poor System Engineering  Leads to poor design, coding, and testing   Cycle of Penetrate and Patch Piecemeal Approach to Security Assurance 5 Reducing Software Security Risk Through an Integrated Approach NASA • Software Vulnerabilities Expose IT Systems and Infrastructure to Security Risks • Goal: Reduce Security Risk in Software and Protect IT Systems, Data, and Infrastructure •Security Training for System Engineers and Developers V m atrix A ttack s n ot in th e w ild •Software Security Checklist for end-to-end life cycle •Software Security Assessment Instrument (SSAI) PBT C1 C2 C3 C4 •Security Instrument Includes: •Model-Based Verification •Property-Based Testing •Security Checklist •Vulnerability Matrix •Collection of security tools 6 MC D iscovered a ttack s n ot b een seen in th e w ild K n o w n attack s for V m atrix / P B T Lib aries A nd_1 A nd_2 S a fe U n sa fe T echno lo g y Inte gratio n S oftw are C o m p on en t R elation sh ip s Womb-to-Tomb Process   Coincides with Organizational Polices and Requirements Software Lifecycle Integration  Software Security Checklist     Vulnerability Matrix – NASA Top 20 Security Assurance Instruments   Phase 1  Provide instrument to integrate security as a formal approach to the software life cycle  Requirements Driven Phase 2:  External Release of Software  Release Process  Security Assessment Tools (SATs)   Early Development – Model Checking / FMF Implementation – Property Based Testing Description of available SATs Pros and Cons of each and related tools with web sites  Notification to Users and Functional Areas when Software or Systems are De-Commissioned 7 Current Work  Model-Based Verification of SSL Protocol  Report Submitted to IV&V Center  Integration of Security into Software Quality Improvement (SQI) at JPL   Inclusion of Security in Life Cycle Process Security Risk Assessment – Potential Use of Defect Detection and Prevention Tool  Formal Verification of Patchlink Patch Management Software Agent  Used in All NASA Centers 8 Note on Future Work    Training Course for SSC and Use of Security Assessment Tools Experts and Expert Center Available to Assist with the Instrument and Tools Integrate with Deep Space Mission Systems (DSMS)    Verifying SSL and use in DSMS Potential to Verify Space Link Extension (SLE) Protocol Potential to Verify Space Communication Protocol Standard (SCPS) implementations  Developing an Approach to Project Life Cycle Security Risk Assessment at JPL 9 FOR MORE INFO... David Gilliam JPL 400 Oak Grove Dr., MS 144-210 Pasadena, CA 91109 Phone: (818) 354-0900 FAX: (818) 393-1377 Email: david.p.gilliam@jpl.nasa.gov John Powell MS 125-233 Phone: (818) 393-1377 Email: john.d.powell@jpl.nasa.gov Website: http://rssr.jpl.nasa.gov/ 10

Related docs
SAS Enterprise Guide 4.1
Views: 924  |  Downloads: 47
Using SAS Dates and Times � A Tutorial
Views: 227  |  Downloads: 18
SAS syntax
Views: 1  |  Downloads: 0
SAS LOGO
Views: 10  |  Downloads: 0
sas_pharmacy_y1
Views: 4  |  Downloads: 0
ANCOVA Examples Using SAS
Views: 11  |  Downloads: 1
How to Use a Permanent SAS Data Set
Views: 84  |  Downloads: 10
sas
Views: 0  |  Downloads: 0
How to Create a Permanent SAS Data Set
Views: 882  |  Downloads: 10
premium docs
Other docs by 44aff241486ce2...
INSTRUCTIONS FOR COMPLETING FORM SI-100
Views: 1525  |  Downloads: 11
dv130k
Views: 82  |  Downloads: 0
dv120s
Views: 185  |  Downloads: 0
TORTS -- MASTER
Views: 749  |  Downloads: 70
How to go to Graduate School in Biology
Views: 579  |  Downloads: 7
Massage Therapy Reference Summary
Views: 1178  |  Downloads: 35
ch135
Views: 107  |  Downloads: 0
i-9
Views: 192  |  Downloads: 10
de147
Views: 100  |  Downloads: 0
A Mighty Fortress
Views: 153  |  Downloads: 1
dv145s
Views: 227  |  Downloads: 0
Applying to Graduate School
Views: 904  |  Downloads: 15
Behavioral Economics: Past, Present, Future
Views: 517  |  Downloads: 20