Dynamic verification of security properties – VéDySec
Security risks have become a major concern during the recent years.
A security flaw can be exploited by attackers and allow them to steal
confidential data (personal, medical, financial, industrial, defence, etc.),
to access services without authorisation, or to modify or to compromise
sensible data with a malicious goal (identity usurpation, espionage,
hybrid war, terrorism, etc.)
Static verification techniques, namely by abstract interpretation
or deductive verification, can demonstrate the absence of vulnerabilities
in a software product. However, these techniques remain difficult
and expensive to apply on industrial software.
Indeed, their application requires deep expertise and significant
effort. In this context, developing dynamique verification techniques
for security properties, easier to apply than static techniques,
is necessary for application of these techniques to a large
range of projects.
The goal of the VéDySec project is to consolidate the techniques and tools
for dynamic verification of security properties.
Project coordination
Nikolai KOSMATOV (Thales Research & Technology)
The author of this summary is the project coordinator, who is responsible for the content of this summary. The ANR declines any responsibility as for its contents.
Partnership
LIFO EA 4022 LABORATOIRE D'INFORMATIQUE FONDAMENTALE D'ORLÉANS
TRT Thales Research & Technology
LIST Laboratoire d'Intégration des Systèmes et des Technologies
Help of the ANR 424,598 euros
Beginning and duration of the scientific project:
- 24 Months