Security Assurance

2006-01-10 Thread Marsh David W Maj AFIT/ENG
Tomcat Developers, I'm early in some research focusing on software analyses, specifically those related to data security. As a part of this work I'd like to show through the theory and application that there is in fact no way for protected information to leak out from that code designated to

Re: Security Assurance

2006-01-10 Thread Mladen Turk
Marsh David W Maj AFIT/ENG wrote: Tomcat Developers, While I understand that the libraries and extensions used by Tomcat *should* provide that assurance, what would happen if someone inadvertently wrote some code that could create a new object with rights never intended by developers? What I

Re: Security Assurance

2006-01-10 Thread Mladen Turk
Marsh David W Maj AFIT/ENG wrote: What I would consider useful is a 'compile time note' There would have to be a way to capture design intent through explicit markers (or perhaps an inference) identifying both the protected code and those code segments that are allowed to access the protected