首页> 外文会议>ACM SIGMOD international conference on Management of data >Static detection of security flaws in object-oriented databases
【24h】

Static detection of security flaws in object-oriented databases

机译:静态检测面向对象数据库中的安全漏洞

获取原文

摘要

Access control in function granularity is one of the features of many object-oriented databases. In those systems, the users are granted rights to invoke composed functions instead of rights to invoke primitive operations. Although primitive operations are invoked inside composed functions, the users can invoke them only through the granted functions. This achieves access control in abstract operation level. Access control utilizing encapsulated functions, however, easily causes many "security flaws" through which malicious users can bypass the encapsulation and can abuse the primitive operations inside the functions. In this paper, we develop a technique to statically detect such security flaws. First, we design a framework to describe security requirements that should be satisfied. Then, we develop an algorithm that syntactically analyzes program code of the functions and determines whether given security requirements are satisfied or not. This algorithm is sound, that is, whenever there is a security flaw, it detects it.
机译:函数粒度中的访问控制是许多面向对象的数据库的功能之一。在那些系统中,授予用户调用组合功能的权限,而不是调用原始操作的权限。尽管原始操作是在组合函数中调用的,但是用户只能通过授予的函数来调用它们。这样可以实现抽象操作级别的访问控制。但是,利用封装功能的访问控制容易造成许多“安全漏洞”,恶意用户可以通过这些漏洞绕过封装并滥用功能内部的原始操作。在本文中,我们开发了一种静态检测此类安全漏洞的技术。首先,我们设计一个框架来描述应满足的安全要求。然后,我们开发了一种算法,该算法对功能的程序代码进行语法分析,并确定是否满足给定的安全性要求。该算法是合理的,也就是说,只要存在安全漏洞,它就会检测到它。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号