Paper published in a book (Scientific congresses, symposiums and conference proceedings)
The AVANTSSAR Platform for the Automated Validation of Trust and Security of Service-Oriented Architectures
Armando, Alessandro; Arsac, Wihem; Avanesov, Tigran et al.
2012In Proceedings of 18th International Conference "Tools and Algorithms for the Construction and Analysis of Systems", as Part of the European Joint Conferences on Theory and Practice of Software, ETAPS 2012, Tallinn, Estonia, March 24 - April 1, 2012.
Peer reviewed
 

Files


Full Text
tacas12.pdf
Publisher postprint (304.71 kB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Abstract :
[en] The AVANTSSAR Platform is an integrated toolset for the formal specification and automated validation of trust and security of service-oriented architectures and other applications in the Internet of Services. The platform supports application-level specification languages (such as BPMN and our custom languages) and features three validation backends (CL-AtSe, OFMC, and SATMC), which provide a range of complementary automated reasoning techniques (including service orchestration, compositional reasoning, model checking, and abstract interpretation). We have applied the platform to a large number of industrial case studies, collected into the AVANTSSAR Library of validated problem cases. In doing so, we unveiled a number of problems and vulnerabilities in deployed services. These include, most notably, a serious flaw in the SAML-based Single Sign-On for Google Apps (now corrected by Google as a result of our findings). We also report on the migration of the platform to industry.
Disciplines :
Computer science
Identifiers :
UNILU:UL-CONFERENCE-2012-439
Author, co-author :
Armando, Alessandro
Arsac, Wihem
Avanesov, Tigran ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Barletta, Michele
Calvi, Alberto
Cappai, Alessandro
Carbone, Roberto
Chevalier, Yannick
Compagna, Luca
Cuéllar, Jorge
Erzse, Gabriel
Frau, Simone
Minea, Marius
Mödersheim, Sebastian
Oheimb, David
Pellegrino, Giancarlo
Ponta, Serenaelisa
Rocchetto, Marco
Rusinowitch, Michael
Torabi Dashti, Mohammad
Turuani, Mathieu
Viganò, Luca
More authors (12 more) Less
Language :
English
Title :
The AVANTSSAR Platform for the Automated Validation of Trust and Security of Service-Oriented Architectures
Publication date :
2012
Event name :
18th International Conference, TACAS 2012,
Event place :
Tallinn, Estonia
Event date :
March 24 - April 1, 2012
Main work title :
Proceedings of 18th International Conference "Tools and Algorithms for the Construction and Analysis of Systems", as Part of the European Joint Conferences on Theory and Practice of Software, ETAPS 2012, Tallinn, Estonia, March 24 - April 1, 2012.
Publisher :
Springer Berlin Heidelberg
ISBN/EAN :
978-3-642-28755-8
Pages :
267-282
Peer reviewed :
Peer reviewed
Commentary :
7214 2012 Proceedings of 18th International Conference, TACAS 2012, Lecture Notes in Computer Science
Available on ORBilu :
since 12 July 2013

Statistics


Number of views
96 (5 by Unilu)
Number of downloads
1 (1 by Unilu)

Scopus citations®
 
76
Scopus citations®
without self-citations
39
OpenCitations
 
56

Bibliography


Similar publications



Contact ORBilu