New tool aims to ensure software security policies reflect user needs

Oct 30, 2012

Researchers from North Carolina State University and IBM Research have developed a new natural language processing tool that businesses or other customers can use to ensure that software developers have a clear idea of the security policies to be incorporated into new software products.

Specifically, the research focuses on access control policies (ACPs), which are the security requirements that need to bear in mind when developing new software. For example, an ACP for a university grading program needs to allow professors to give grades to students, but should not allow students to change the grades.

"These ACPs are important, but are often buried amidst a lengthy list of other requirements that customers give to developers," says Dr. Tao Xie, an associate professor of at NC State and co-author of a paper on the research. These requirements are written in "natural language," which is the conversational language that people use when talking or corresponding via the written word.

Incomplete or inaccurate ACP requirements can crop up, for example, if the customer writing the ACP requirements makes a mistake or doesn't have enough technical know-how to accurately describe a program's security needs.

A second problem is that programmers may misinterpret some ACP requirements, or overlook them entirely.

In collaboration with IBM Research, Xie's research team has developed a solution that uses a program to extract the ACP requirements from a customer's overall list of requirements and translate it into machine-readable language that computers can understand and enforce.

After the ACPs are extracted, they can be run through Access Control Policy Tool (ACPT) – also developed in Xie's research team in collaboration with the National Institute of Standards and Technology (NIST) – which verifies and tests the ACPs and determines whether the ACP requirements are adequate to meet the security needs of the program.

Once the ACP requirements have been translated into machine-readable language, they can also be incorporated into a policy-enforcement "engine" in the final software product – which ensures that ACPs cannot be overlooked by programmers.

"In general, developing a program that understands natural language text is very challenging," Xie says. "However, ACP requirements in software documents usually follow a certain style, using terms such as 'cannot be edited' or 'does not have the ability to edit.' Because ACPs tend to use such a limited number of phrases, it is much easier to develop a program that effectively translates natural language texts in this context."

Explore further: Review: 'Hearthstone' card game is the real deal

More information: people.engr.ncsu.edu/txie/publications/fse12-nlp.pdf

add to favorites email to friend print save as pdf

Related Stories

Study analyzes emotions in software engineering

Feb 13, 2012

Emotions are an important factor that must be taken into account when designing any type of software. This is the conclusion reached through a research project coordinated by the Universidad Carlos III de ...

New programming language to plug information leaks in software

Nov 23, 2011

The current method for preventing users and unauthorised individuals from obtaining information to which they should not have access in data programs is often to have code reviewers check the code manually, looking for potential ...

Recommended for you

Review: 'Hearthstone' card game is the real deal

6 hours ago

Video game publishers don't take many risks with their most popular franchises. You know exactly what you are going to get from a new "Call of Duty" or "Madden NFL" game—it will probably be pretty good, ...

Microsoft expands ad-free Bing search for schools

Apr 23, 2014

Microsoft is expanding a program that gives schools the ability to prevent ads from appearing in search results when they use its Bing search engine. The program, launched in a pilot program earlier this year, is now available ...

Growing app industry has developers racing to keep up

Apr 20, 2014

Smartphone application developers say they are challenged by the glut of apps as well as the need to update their software to keep up with evolving phone technology, making creative pricing strategies essential to finding ...

Android gains in US, basic phones almost extinct

Apr 18, 2014

The Google Android platform grabbed the majority of mobile phones in the US market in early 2014, as consumers all but abandoned non-smartphone handsets, a survey showed Friday.

User comments : 0

More news stories

Amazon launches grocery service for Prime members

Amazon is taking aim at grocery stores and discounters like Wal-Mart with a grocery service that lets its Prime loyalty club members fill up to a 45-pound box with groceries and get it shipped for a flat rate of $5.99.

Facebook buys fitness app Moves

Facebook has bought the fitness app Moves, which helps users monitor daily physical activity and their calorie counts on a smartphone.

Study links California drought to global warming

While researchers have sometimes connected weather extremes to man-made global warming, usually it is not done in real time. Now a study is asserting a link between climate change and both the intensifying California drought ...