
Engineering Secure Software and Systems
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
More details
Other editions
Additional editions

Content
- Title Page
- Preface
- Organization
- Table of Contents
- Application-Replay Attack on Java Cards: When the Garbage Collector Gets Confused
- Introduction
- Java Card Reference Prediction
- Reference Assignment
- Garbage Collection
- Reference Prediction
- Application Replay to Circumvent the Application Firewall
- Java Card Context Isolation : The Application Firewall
- Application Instance Deletion
- Application-Replay" Attack on a Java Card 3.0
- Analysis and Countermeasures
- Conclusion
- References
- Supporting the Development and Documentation of ISO 27001 Information Security Management Systems through Security Requirements Engineering Approaches
- Introduction
- The ISO 27001 Standard
- A Conceptual Framework for Security Requirements Engineering
- Relating the ISO 27001 Standard and Security Requirements Engineering Methods
- Insights
- Related Work
- Conclusion
- References
- Typed Assembler for a RISC Crypto-Processor
- Introduction
- ype-Checking
- Assembler Typing
- The Basic Algorithm
- Taking Account of the Stack
- Conclusion
- Future Work
- References
- Transversal Policy Conflict Detection
- Introduction
- Related Work
- Use Case
- Transversal Conflict Detection
- Domain Description Model
- Class-Specific Policy Models
- Conflict Specification Model
- Conclusion
- References
- Challenges in Implementing an End-to-End Secure Protocol for Java ME-Based Mobile Data Collection in Low-Budget Settings
- Introduction
- Implementation Challenges and Solutions
- Cryptography API Providers
- Key Generation
- Secure Data Upload and Download
- Secure Storage
- Modularity of the API
- API Integration
- Preliminary Performance Test
- Related Work and Conclusions
- References
- Runtime Enforcement of Information Flow Security in Tree Manipulating Processes
- Introduction
- Preliminaries
- The Runtime Monitor
- Formal Treatment of the Monitor
- Guarantees
- Related Work and Conclusion
- References
- Formalisation and Implementation of the XACML Access Control Mechanism
- Introduction
- The XACML Standard
- An Alternative Syntax of XACML
- XACML Formal Semantics
- Tools
- Concluding Remarks
- References
- A Task Ordering Approach for Automatic Trust Establishment
- Introduction
- Related Work
- A Graph-Based Trust Metric Model
- Tasks Dependencies
- Motivation
- Task Domain
- Trust Assumptions
- Model for Automatic Trust Values Computation
- Tasks Comparison
- Case Study: Electronic Health Records Management
- e-Health
- Application of the Model
- Conclusions and Future Work
- References
- An Idea of an Independent Validation of Vulnerability Discovery Models
- Introduction
- Contribution of This Paper
- Research Questions
- Vulnerability Discovery Models
- Validation of VDMs
- Threats to Validity
- Conclusion and Future Work
- References
- A Sound Decision Procedure for the Compositionality of Secrecy
- Introduction
- Preliminaries
- Decision Procedure
- An Insecure Variant of the TLS Protocol
- Validation and Efficiency
- Related Work
- Conclusions
- References
- Plagiarizing Smartphone Applications: Attack Strategies and Defense Techniques
- Introduction
- System and Threat Model
- Android Development Process
- Threat Model
- Obfuscation Model
- Plagiarizing Applications
- Plagiarism Mechanisms and Payload
- Improving Infection Count
- Detecting Plagiarized Applications
- Reverse Engineering and Fingerprinting Android Applications
- Detection Techniques
- Defense Evaluation
- Real-World Plagiarism Detection
- Accuracy
- Obfuscation Resilience
- Computational Feasibility
- Related Work
- Conclusion
- References
- Design of Adaptive Security Mechanisms for Real-Time Embedded Systems
- Introduction
- Background and Motivation
- Approach
- Log Information and Adaptation Mechanism
- Implementation Details
- Evaluation
- Discussion
- Related Work
- Conclusion and Future Work
- References
- Hunting Application-Level Logical Errors
- Introduction
- Related Work
- The APP_LogGIC Framework
- The Invariant-Based Analysis Method (IBM)
- Fuzzy Logic System
- Implementation
- Limitations
- Conclusions and Further Research
- References
- Optimal Trust Mining and Computingon Keyed Map Reduce
- Introduction
- The Motivation Problem
- This Work
- A Keyed MapReduce
- A Keyed MapReduce Function
- Trust Mining on MapReduce
- Pseudonymous of Users
- Trust Mining
- Trust Computing
- Conclusion
- References
- Author Index
System requirements
File format: PDF
Copy protection: Watermark-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Use the free software Adobe Reader, Adobe Digital Editions, or any other PDF viewer of your choice (see eBook Help).
- Tablet/Smartphone (Android; iOS): Install the free app Adobe Digital Editions or another reading app for eBooks, e.g., PocketBook (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (only limited: Kindle).
The file format PDF always displays a book page identically on any hardware. This makes PDF suitable for complex layouts such as those used in textbooks and reference books (images, tables, columns, footnotes). Unfortunately, on the small screens of e-readers or smartphones, PDFs are rather annoying, requiring too much scrolling.
This eBook uses Watermark-DRM, a „soft” copy protection. This means that there are no technical restrictions to prevent illegal distribution. However, there is a personalised watermark embedded in the eBook that can be used to identify the purchaser of the eBook in the event of misuse and to provide evidence for legal purposes.
For more information, see our eBook Help page.