• Deutsch
Login

Open Access

  • Home
  • Search
  • Browse
  • Publish/report a document
  • Help

Refine

Has Fulltext

  • no (12)
  • yes (4)

Author

  • Katkalov, Kuzman (16)
  • Reif, Wolfgang (15)
  • Stenzel, Kurt (15)
  • Borek, Marian (11)
  • Moebius, Nina (4)
  • Fischer, Peter (3)
  • Schellhorn, Gerhard (1)

Year of publication

  • 2017 (2)
  • 2016 (2)
  • 2015 (5)
  • 2014 (2)
  • 2013 (2)
  • 2012 (1)

Document Type

  • Article (7)
  • Part of a Book (6)
  • Report (2)
  • Doctoral Thesis (1)

Language

  • English (15)
  • German (1)

Keywords

  • Informationsfluss (3)
  • Modellgetriebene Entwicklung (3)
  • model-driven development (2)
  • Android (platform) (1)
  • Android <Systemplattform> (1)
  • Codegenerierung (1)
  • Computersicherheit (1)
  • Modelltransformation (1)
  • Softwareentwicklung (1)
  • Verifikation (1)
+ more

Institute

  • Fakultät für Angewandte Informatik (16)
  • Institut für Informatik (16)
  • Institut für Software & Systems Engineering (15)
  • Lehrstuhl für Softwaretechnik (15)

16 search hits

  • 1 to 16
  • 10
  • 20
  • 50
  • 100

Sort by

  • Year
  • Year
  • Title
  • Title
  • Author
  • Author
Model-Driven Code Generation for Information Flow Secure Systems with IFlow (2012)
Katkalov, Kuzman ; Fischer, Peter ; Stenzel, Kurt ; Reif, Wolfgang
As personal information moves from home computers to mobile devices, protection against information leaks and data theft becomes an increasingly important and current issue. We develop a model-driven approach called IFlow which allows a developer to model mobile Android applications with complex information flow properties using UML. Using model-to-model and model-to-code transformations we generate code skeletons for those applications and verify noninterference properties using a language-based approach. Further, we will use those properties as lemmas for a formal verification of an automatically generated formal representation of the modeled application. In this report, we focus on automatic code generation, evaluation of language-based information flow control solutions and deployment of generated code to target platforms.
Formal Verification of Information Flow Secure Systems with IFlow (2012)
Fischer, Peter ; Katkalov, Kuzman ; Stenzel, Kurt ; Reif, Wolfgang
This report presents an approach called IFlow which allows the model-driven development of secure systems regarding information flow. The approach focuses on the application domain of mobile applications and web services. A developer starts by creating an abstract UML model of a system where he can additionally specify information flow properties the system must satisfy. From the model, Java code is generated together with an information flow policy that can be checked by automated analysis tools like Jif or Joana. In addition, the UML model is transformed into a formal specification which is the basis for formal reasoning within our formal framework including the interactive theorem prover KIV. While automated tools are designed for the simple property of noninterference, formal verification allows to express more complex properties. In order that the results of verification can be carried to the code level and that the results of automated code analysis can be used as lemmas for formal verification, an information flow-preserving refinement relation is established between the formal specification and the code. The focus of this report is on the aspects of formal verification.
Ein modellgetriebener Ansatz zur Entwicklung informationsflusssicherer Systeme (2017)
Katkalov, Kuzman
Die allgegenwärtigen und immer verbundenen mobilen Geräte sammeln große Mengen an persönlichen Daten über ihre Nutzer. In vielen Fällen wird die Vertraulichkeit solcher Daten nicht garantiert; so kommt es bei mobilen Apps und Webservices oft zu Datenlecks, wodurch die Privatsphäre ihrer Nutzer verletzt wird. Diese Arbeit stellt den modellgetriebenen Ansatz IFlow zur Entwicklung informationsflusssicherer Anwendungen bestehend aus mobilen Apps und Webservices vor. Hierzu wird mit der Modellierungssprache Modelflow das Modell einer sicherheitskritischen Anwendung erstellt und ihre Informationsflusseigenschaften spezifiziert. Anschließend können diese Eigenschaften mit Hilfe vollautomatischer Informationsflussanalyse sowie interaktiver Verifikation garantiert werden. Die finale Anwendung besteht aus Android-Apps und Java-Webservices, die aus dem Modell generiert werden, und die modellierten Informationsflusseigenschaften erfüllen.
Code Abstractions for Automatic Information Flow Control in a Model-Driven Approach (2017)
Katkalov, Kuzman ; Stenzel, Kurt ; Reif, Wolfgang
Secure integration of third party components in a model-driven approach (2016)
Borek, Marian ; Stenzel, Kurt ; Katkalov, Kuzman ; Reif, Wolfgang
Declassification of information with complex filter functions (2016)
Stenzel, Kurt ; Katkalov, Kuzman ; Borek, Marian ; Reif, Wolfgang
A model-driven approach to noninterference (2015)
Stenzel, Kurt ; Katkalov, Kuzman ; Borek, Marian ; Reif, Wolfgang
Evaluation of Jif and Joana as information flow analyzers in a model-driven approach (2013)
Katkalov, Kuzman ; Fischer, Peter ; Stenzel, Kurt ; Moebius, Nina ; Reif, Wolfgang
Model-driven testing of security protocols with SecureMDD (2012)
Katkalov, Kuzman ; Moebius, Nina ; Stenzel, Kurt ; Borek, Marian ; Reif, Wolfgang
Abstracting security-critical applications for model checking in a model-driven approach (2015)
Borek, Marian ; Stenzel, Kurt ; Katkalov, Kuzman ; Reif, Wolfgang
Integrating a model-driven approach and formal verification for the development of secure service applications (2015)
Borek, Marian ; Katkalov, Kuzman ; Moebius, Nina ; Reif, Wolfgang ; Schellhorn, Gerhard ; Stenzel, Kurt
Integration and exchangeability of external security-critical web services in a model-driven approach (2015)
Borek, Marian ; Stenzel, Kurt ; Katkalov, Kuzman ; Reif, Wolfgang
Modeling information flow properties with UML (2015)
Katkalov, Kuzman ; Stenzel, Kurt ; Borek, Marian ; Reif, Wolfgang
Formalizing information flow control in a model-driven approach (2014)
Stenzel, Kurt ; Katkalov, Kuzman ; Borek, Marian ; Reif, Wolfgang
Model-driven development of information flow-secure systems with IFlow (2013)
Katkalov, Kuzman ; Stenzel, Kurt ; Borek, Marian ; Reif, Wolfgang
Modeling test cases for security protocols with SecureMDD (2014)
Katkalov, Kuzman ; Moebius, Nina ; Stenzel, Kurt ; Borek, Marian ; Reif, Wolfgang
  • 1 to 16

OPUS4 Logo

  • Contact
  • Imprint
  • Sitelinks