A Model Checker for the Verification of Browser Based Protocols

Autores/as

  • Victor Ferman Tecnologico de Monterrey, Escuela de Ingeniería y Ciencias, Atizapán de Zaragoza, Estado de México
  • Raúl Monroy Tecnológico de Monterrey, Escuela de Ingeniería y Ciencias
  • Dieter Hutter German Research Center for Artificial Intelligence, Universität Bremen, Germany

DOI:

https://doi.org/10.13053/cys-21-1-2483

Palabras clave:

Model checking, browser based protocols, security protocols, formal methods

Resumen

A browser based protocol is the chief security component of a safety critical web application, such as e-banking. Accordingly, browser based protocols need to be thoroughly verified in order to guarantee they are up to comply with key security properties. To this end, we have developed WebMC, a model checker especially designed to consider web standards, with the aim of analyzing browser based protocol execution, as encompassed by the interactions of a typical user, a browser, and active attacker playing the role of the network, and one or more servers. In this paper, we shall show how to use WebMC in the design and the development of browser based protocols. Our tool has been successfully validated: WebMC has been able to reproduce a number of the verification results found in the literature, but fully automatically.

Biografía del autor/a

Victor Ferman, Tecnologico de Monterrey, Escuela de Ingeniería y Ciencias, Atizapán de Zaragoza, Estado de México

Raúl Monroy, Tecnológico de Monterrey, Escuela de Ingeniería y Ciencias

Dieter Hutter, German Research Center for Artificial Intelligence, Universität Bremen, Germany

Descargas

Publicado

2017-03-20