Mandatory Access Control for Android Application Security

2016 ◽  
Vol 43 (3) ◽  
pp. 275-288 ◽  
Author(s):  
June-sung Na ◽  
Do-Yun Kim ◽  
Wooguil Pak ◽  
Young-June Choi
2018 ◽  
Vol 6 (5) ◽  
pp. 840-847
Author(s):  
Shalabh Agarwal ◽  
◽  
◽  
◽  
◽  
...  

2009 ◽  
Vol 32 (4) ◽  
pp. 730-739 ◽  
Author(s):  
Xin-Song WU ◽  
Zhou-Yi ZHOU ◽  
Ye-Ping HE ◽  
Hong-Liang LIANG ◽  
Chun-Yang YUAN

Author(s):  
VINCENT C. HU ◽  
D. RICHARD KUHN ◽  
TAO XIE ◽  
JEEHYUN HWANG

Mandatory access control (MAC) mechanisms control which users or processes have access to which resources in a system. MAC policies are increasingly specified to facilitate managing and maintaining access control. However, the correct specification of the policies is a very challenging problem. To formally and precisely capture the security properties that MAC should adhere to, MAC models are usually written to bridge the rather wide gap in abstraction between policies and mechanisms. In this paper, we propose a general approach for property verification for MAC models. The approach defines a standardized structure for MAC models, providing for both property verification and automated generation of test cases. The approach expresses MAC models in the specification language of a model checker and expresses generic access control properties in the property language. Then the approach uses the model checker to verify the integrity, coverage, and confinement of these properties for the MAC models and finally generates test cases via combinatorial covering array for the system implementations of the models.


2021 ◽  
Vol 9 (02) ◽  
pp. 95-99
Author(s):  
Abriza Mahandis Shama ◽  
Dian W. Chandra

PT. Emporia Digital Raya is an fintech company. The product include web and android application. However, in the deployment system, PT Emporia Digital Raya still uses an ancient system with a single vm system and only uses git for deployment to server. Even though at this time the deployment process of an application has grown very far. Therefore, in this study will created a system which is currently popular being used. This system is called DevSecOps. Devsecops will need a tools like Jenkins, Sonarqube, and Docker. The core of this system is the automation process where the deployment process is no longer done manually as before. With this system, it is hoped that will help speed up developer work and improve code quality.


Sign in / Sign up

Export Citation Format

Share Document