Security for Automated, Distributed Configuration Management

``Security for Automated, Distributed Configuration Management'' by P. Devanbu, M. Gertz, and S. Stubblebine. In ICSE Workshop on Software Engineering over the Internet, Apr. 1999.
Annotation: Identifies security issues for automatic software management and a research plan to address them. Integrity must be guaranteed for the software being shipped from vendor to user, the user's configuration, and messages from user to vendor that describe configurations. Authentication is needed to identify software vendors and licenced software users. Privacy protections are needed for software components (because of their intellectual property value) and for software configurations (because they may reveal sensitive data). Finally, delegation is needed, e.g., to let administrators delegate configuration control to vendors and to let vendors delegate configuration checking to a testing lab.

