首页> 外文会议>Association for Computing Machinery Conference on Computer and Communications Security >Towards Automatic Reverse Engineering of Software Security Configurations
【24h】

Towards Automatic Reverse Engineering of Software Security Configurations

机译:朝向软件安全配置的自动逆向工程

获取原文

摘要

The specifications of an application's security configuration are crucial for understanding its security policies, which can be very helpful in security-related contexts such as misconfiguration detection. Such specifications, however, are often ill-documented, or even close because of the increasing use of graphic user interfaces to set program options. In this paper, we propose ConfigRE, a new technique for automatic reverse engineering of an application's access-control configurations. Our approach first partitions a configuration input into fields, and then identifies the semantic relations among these fields and the roles they play in enforcing an access control policy. Based upon such knowledge, ConfigRE automatically generates a specification language to describe the syntactic relations of these fields. The language can be converted into a scanner using standard parser generators for scanning configuration files and discovering the security policies specified in an application. We implemented ConfigRE in our research and evaluated it against real applications. The experiment results demonstrate the efficacy of our approach.
机译:应用程序安全配置的规范对于了解其安全策略至关重要,这可能在安全相关的上下文中非常有用,例如错误配置检测。然而,此类规范通常是不明智的,甚至关闭,因为使用图形用户界面的使用来设置程序选项。在本文中,我们建议Configre,一种用于应用程序访问控制配置的自动逆向工程的新技术。我们的方法首先将配置输入分区为字段,然后标识这些字段之间的语义关系以及它们在执行访问控制策略时扮演的角色。基于此类知识,Configre自动生成规范语言以描述这些字段的语法关系。可以使用标准解析器生成器将语言转换为扫描仪,用于扫描配置文件并发现应用程序中指定的安全策略。我们在研究中实施了Configre,并评估了真实应用程序。实验结果表明了我们的方法的功效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号