首页> 外文会议> >Retrofitting Legacy Code for Authorization Policy Enforcement
【24h】

Retrofitting Legacy Code for Authorization Policy Enforcement

机译:翻新旧版授权政策执行代码

获取原文

摘要

Researchers have argued that the best way to construct a secure system is to proactively integrate security into the design of the system. However, this tenet is rarely followed because of economic and practical considerations. Instead, security mechanisms are added as the need arises, by retrofitting legacy code. Existing techniques to do so are manual and ad hoc, and often result in security holes. We present program analysis techniques to assist the process of retrofitting legacy code for authorization policy enforcement. These techniques can be used to retrofit legacy servers, such as X window, web, proxy, and cache servers. Because such servers manage multiple clients simultaneously, and offer shared resources to clients, they must have the ability to enforce authorization policies. A developer can use our techniques to identify security-sensitive locations in legacy servers, and place reference monitor calls to mediate these locations. We demonstrate our techniques by retrofitting the X11 server to enforce authorization policies on its X clients.
机译:研究人员认为,构建安全系统的最佳方法是将安全性主动地集成到系统的设计中。但是,出于经济和实际考虑,很少遵循此原则。取而代之的是,通过改进旧版代码,在需要时添加安全性机制。这样做的现有技术是手动和临时的,通常会导致安全漏洞。我们提出了程序分析技术,以协助为授权策略实施而改造旧代码的过程。这些技术可用于改造旧式服务器,例如X窗口,Web,代理和缓存服务器。由于此类服务器同时管理多个客户端,并向客户端提供共享资源,因此它们必须具有强制执行授权策略的能力。开发人员可以使用我们的技术来识别旧服务器中对安全敏感的位置,并发出引用监视器调用以调解这些位置。我们通过改装X11服务器以在其X客户端上执行授权策略来展示我们的技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号