Robert J. Ellison
Carnegie Mellon University
Network
Latest external collaboration on country level. Dive into details by clicking on the dots.
Publication
Featured researches published by Robert J. Ellison.
IEEE Software | 1999
Robert J. Ellison; Richard C. Linger; Thomas A. Longstaff; Nancy R. Mead
The Survivable Network Analysis method permits assessment of survivability at the architecture level. Steps include system mission and architecture definition, essential capability definition, compromisable capability definition, and survivability analysis of architectural soft-spots that are both essential and compromisable. The article summarizes application of the method to a subsystem of a large-scale, distributed health care system.
Journal of Systems and Software | 1985
Robert J. Ellison; Barbara J. Staudt
The GANDALF System is used to generate highly interactive software development environments. This paper describes some design decisions made during the development of the GANDALF system and the systems applicability to the generation of single-user programming environments and multi-user software development environments.
hawaii international conference on system sciences | 2010
Robert J. Ellison; Carol Woody
As outsourcing and expanded use of commercial off-the-shelf (COTS) products increase, supply-chain risk becomes a growing concern for software acquisitions. Supply-chain risks for hardware procurement include manufacturing and delivery disruptions, and the substitution of counterfeit or substandard components. Software supply-chain risks include third-party tampering with a product during development or delivery, and, more likely, a compromise of the software assurance through the introduction of software defects. This paper describes practices that address such defects and mechanisms for introducing these practices into the acquisition life cycle. The practices improve the likelihood of predictable behavior by systematically analyzing data flows to identify assumptions and using knowledge of attack patterns and vulnerabilities to analyze behavior under conditions that an attacker might create.
hawaii international conference on system sciences | 2011
Christopher J. Alberts; Audrey J. Dorofee; Rita Creel; Robert J. Ellison; Carol Woody
In todays business environment, multiple organizations must routinely work together in software supply chains when acquiring, developing, operating, and maintaining software products. The programmatic and product complexity inherent in software supply chains increases the risk that defects, vulnerabilities, and malicious code will be inserted into a delivered software product. As a result, effective risk management is essential for establishing and maintaining software supply-chain assurance over time. The Software Engineering Institute (SEI) is developing a systemic approach for assessing and managing software supply-chain risks. This paper highlights the basic approach being implemented by SEI researchers and provides a summary of the status of this work.
computer and communications security | 2003
Andrew P. Moore; Robert J. Ellison
High confidence in a systems survivability requires an accurate understanding of the systems threat environment and the impact of that environment on system operations. This paper describes a framework for intrusion-aware design called trustworthy refinement through intrusion-aware design (TRIAD). The spiral structure of TRIAD iterates through three sectors of activity for developing the architectural strategy, for instantiating the architecture using technical components, and for analyzing the impact of the threat environment on system operations. TRIAD helps developers of complex, internetworked information systems to formulate, implement, and maintain a coherent, justifiable, and affordable survivability strategy that addresses mission-compromising threats for their organization. TRIAD facilitates planning for the inevitable change to the threat and operational environment and helps trace the effect of change back to the survivability requirements and architecture.
Archive | 1999
Robert J. Ellison; David A. Fisher; Richard C. Linger; Howard F. Lipson; Thomas A. Longstaff; Nancy R. Mead
Archive | 2001
Andrew P. Moore; Robert J. Ellison; Richard C. Linger
Archive | 2000
Nancy R. Mead; Robert J. Ellison; Richard C. Linger; Thomas A. Longstaff; John McHugh
Archive | 2008
Julia H. Allen; Sean Barnum; Robert J. Ellison; Gary McGraw; Nancy R. Mead
Archive | 2003
Robert J. Ellison; Anthony J. Lattanze; Judith A. Stafford; Charles B. Weinstock; William G. Wood