2009Unpublished venueRequires access

Security-oriented program transformations

Munawar Hafiz, Ralph E. Johnson

Open publisher page 6 citations

Abstract

Security experts generally believe that, "security cannot be added on, it must be designed from the beginning" [1]. This is because the typical way of improving system security by patches is ad hoc and has not produced good results. My work shows that retrofitting security does not need to be a massive reengineering effort, nor does it need to be ad hoc. Security solutions can be added through systematic, general purpose security-oriented program transformations. I have been maintaining a catalog of security-oriented program transformations; so far the catalog contains forty two transformations. These transformations improve the traditional approaches of security engineering and keep software secure in the face of new security threats.

About this research paper

What this paper is about

Security experts generally believe that, "security cannot be added on, it must be designed from the beginning" [1]. This is because the typical way of improving system security by patches is ad hoc and has not produced good results. My work shows that retrofitting security does not need to be a massive reengineering effort, nor does it need to be ad hoc. Security solutions can be added through systematic, general purpose security-oriented program transformations. I have been maintaining a catalog of security-oriented program transformations; so far the catalog contains forty two transformations. These transformations improve the traditional approaches of security engineering and keep software secure in the face of new security threats.

Why it matters

OpenAlex reports 6 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Security experts generally believe that, "security cannot be added on, it must be designed from the beginning" [1]. This is because the typical way of improving system security by patches is ad hoc and has not produced good results. My work shows that retrofitting security does not need to be a massive reengineering effort, nor does it need to be ad hoc. Security solutions can be added through systematic, general purpose security-oriented program transformations. I have been maintaining a catalog of security-oriented program transformations; so far the catalog contains forty two transformations. These transformations improve the traditional approaches of security engineering and keep software secure in the face of new security threats.

Key concepts: Computer science, Security service, Cloud computing security, Computer security, Security testing, Security engineering, Security through obscurity, Software security assurance

Related papers

Back to paper searchBrowse research topicsOriginal source
Security-oriented program transformations — Research Paper | ScholarLens