首页> 外文OA文献 >Retrofitting Legacy Code for Authorization Policy Enforcement
【2h】

Retrofitting Legacy Code for Authorization Policy Enforcement

机译:改进授权政策执行的遗留代码

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Researchers have long argued that the best way to construct a secure system is to proactively integrate security into the design of the system. However, this tenet is rarely followed because of economic and practical considerations. Instead, security mechanisms are added as the need arises, by retrofitting legacy code. Unfortunately, existing techniques to do so are manual and adhoc, and often result in security holes in the retrofitted code. We show that program analysis techniques can be used to securely, and largely automatically, retrofit legacy code for authorization policy enforcement. Our techniques are applicable to a large class of legacy servers, namely those that simultaneously manage multiple clients, possibly with different security labels. It is important for such servers to ensure that client interaction is governed by an authorization policy. We demonstrate our ideas using two program analysis tools we built, Aid and Alpen, which work together to automate the process of retrofitting legacy servers with mechanisms for authorization policy enforcement. We show that an X server retrofitted using these tools securely enforces authorization policies on its X clients.
机译:长期以来,研究人员一直认为,构建安全系统的最佳方法是将安全性主动地集成到系统的设计中。但是,出于经济和实际考虑,很少遵循此原则。取而代之的是,通过改型旧代码,在需要时添加安全机制。不幸的是,这样做的现有技术是手动和临时的,并且经常在翻新代码中导致安全漏洞。我们展示了程序分析技术可以用来安全地,并且在很大程度上自动地改造旧版代码以执行授权策略。我们的技术适用于大量传统服务器,即那些同时管理多个客户端(可能带有不同安全标签)的服务器。对于此类服务器,确保客户端交互受授权策略控制非常重要。我们使用我们构建的两个程序分析工具Aid和Alpen展示了我们的想法,这两个工具一起工作以使用授权策略实施机制来自动化旧服务器的改造过程。我们表明,使用这些工具进行改装的X服务器可以在其X客户端上安全地执行授权策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号