Search NASASearch

NASA NTRS · 20070017438

Security Verification Techniques Applied to PatchLink COTS Software

Abstract

Verification of the security of software artifacts is a challenging task. An integrated approach that combines verification techniques can increase the confidence in the security of software artifacts. Such an approach has been developed by the Jet Propulsion Laboratory (JPL) and the University of California at Davis (UC Davis). Two security verification instruments were developed and then piloted on PatchLink's UNIX Agent, a Commercial-Off-The-Shelf (COTS) software product, to assess the value of the instruments and the approach. The two instruments are the Flexible Modeling Framework (FMF) -- a model-based verification instrument (JPL), and a Property-Based Tester (UC Davis). Security properties were formally specified for the COTS artifact and then verified using these instruments. The results were then reviewed to determine the effectiveness of the approach and the security of the COTS product.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Gilliam, David P., Powell, John D., Bishop, Matt, Andrew, Chris, Jog, Sameer. 2006-06-26. Security Verification Techniques Applied to PatchLink COTS Software. https://ntrs.nasa.gov/citations/20070017438

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related reports

Operational modification of the Mars Exploration Rovers flight software

The Mars Exploration Rovers (MER)Flight Software (FSW) was designed from the outset to be modified during operations. This paper discusses the content of the uplink products that are sent to the Rover, the planning of the Patch and Load activities, the testing of the products and prcedures, and the actual operations themselves.

patch