<?xml version="1.0" encoding="UTF-8"?>
<b:Sources SelectedStyle="" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography"  xmlns="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" >
<b:Source>
<b:Tag>brucker.ea:verification:2005</b:Tag>
<b:SourceType>ArticleInAPeriodical</b:SourceType>
<b:City>Heidelberg</b:City>
<b:Publisher>Springer-Verlag</b:Publisher>
<b:Year>2005</b:Year>
<b:PeriodicalName>International Journal on Software Tools for Technology (STTT)</b:PeriodicalName>
<b:Volume>7</b:Volume>
<b:Issue>3</b:Issue>
<b:Pages>233-247</b:Pages>
<b:Author>
<b:Author><b:NameList>
<b:Person><b:Last>Brucker</b:Last><b:First>Achim</b:First><b:Middle>D</b:Middle></b:Person>
<b:Person><b:Last>Wolff</b:Last><b:First>Burkhart</b:First></b:Person>
</b:NameList></b:Author>
</b:Author>
<b:Title>A Verification Approach for Applied System Security</b:Title>
<b:Comments>We present a method for the security analysis of realistic models over off-the-shelf systems and their configuration by formal, machine-checked proofs. The presentation follows a large case study based on a formal security analysis of a CVS-Server architecture. The analysis is based on an abstract architecture (enforcing a role-based access control), which is refined to an implementation architecture (based on the usual discretionary access control provided by the \posix environment). Both architectures serve as a skeleton to formulate access control and confidentiality properties. Both the abstract and the implementation architecture are specified in the language Z. Based on a logical embedding of Z into Isabelle/HOL, we provide formal, machine-checked proofs for consistency properties of the specification, for the correctness of the refinement, and for security properties.</b:Comments>
</b:Source>
</b:Sources>

