le-git-imate: Towards Verifiable Web-based Git Repositories

le-git-imate: Towards Verifiable Web-based Git Repositories
复制标题

le-git-imate:迈向可验证的基于 Web 的 Git 存储库

DOI:
10.1145/3196494.3196523
复制
发表时间:
2018
期刊:
Proceedings of the 2018 on Asia Conference on Computer and Communications Security (ASIACCS '18
影响因子:
--
通讯作者:
Cappos, Justin
Cappos, Justin
中科院分区:
--
文献类型:
--
作者:
Afzali, Hammad;Torres-Arias, Santiago;Curtmola, Reza;Cappos, Justin

文献摘要

参考文献

被引文献

相似文献

基于Web的Git托管服务(如GitHub和GitLab)是管理Git存储库并与之交互的热门选择。然而,它们缺少一个重要的安全特性--对Git提交签名的能力。用户指示服务器代表他们执行存储库操作,并且必须相信服务器会忠实地执行他们的请求。这种信任可能是毫无根据的,因为恶意或受损的服务器可能会以不正确的方式执行所请求的操作,导致存储库的状态与用户预期的不同。在本文中,我们展示了一系列高影响力的攻击,当开发人员使用Git托管服务的Web UI执行常见操作时,例如编辑文件或合并分支。然后,我们提出了leg-git-imate,对这些攻击的防御,提供安全保证可比和兼容的Git的标准提交签名机制。我们将le-git-imate实现为Chrome浏览器扩展程序。le-git-imate不需要在服务器端进行更改,因此可以立即使用。它还保留了Github/GitLab中使用的当前工作流,并且不需要用户离开浏览器,它允许任何人验证服务器的操作是否忠实地遵循用户的请求操作。此外,使用浏览器扩展的实验评估表明,le-git-imate具有与Git标准提交签名机制相当的性能。有了我们的解决方案,用户可以在不牺牲安全性的情况下利用GitHub/GitLab基于Web的功能,从而为可验证的基于Web的Git存储库铺平道路。
Web-based Git hosting services such as GitHub and GitLab are popular choices to manage and interact with Git repositories. However, they lack an important security feature - the ability to sign Git commits. Users instruct the server to perform repository operations on their behalf and have to trust that the server will execute their requests faithfully. Such trust may be unwarranted though because a malicious or a compromised server may execute the requested actions in an incorrect manner, leading to a different state of the repository than what the user intended.In this paper, we show a range of high-impact attacks that can be executed stealthily when developers use the web UI of a Git hosting service to perform common actions such as editing files or merging branches. We then propose le-git-imate, a defense against these attacks which provides security guarantees comparable and compatible with Git's standard commit signing mechanism. We implement le-git-imate as a Chrome browser extension. le-git-imate does not require changes on the server side and can thus be used immediately. It also preserves current workflows used in Github/GitLab and does not require the user to leave the browser, and it allows anyone to verify that the server's actions faithfully follow the user's requested actions. Moreover, experimental evaluation using the browser extension shows that le-git-imate has comparable performance with Git's standard commit signature mechanism. With our solution in place, users can take advantage of GitHub/GitLab's web-based features without sacrificing security, thus paving the way towards verifiable web-based Git repositories.
检测网络钓鱼网页
DOI: --
发表时间: 2015
期刊:
影响因子: --
作者:
S. S. Kulkarni;Aastha Mittal;Aniket Nayakawadi
通讯作者: Aniket Nayakawadi
DOI: 10.1109/hicss.2015.625
发表时间: 2015-01
期刊: 2015 48th Hawaii International Conference on System Sciences
影响因子: --
作者:
Russell Shirey;K. Hopkinson;K. E. Stewart;D. Hodson;B. Borghetti
通讯作者: Russell Shirey;K. Hopkinson;K. E. Stewart;D. Hodson;B. Borghetti
并发版本控制系统中的保密性
DOI: --
发表时间: 2006
期刊: Anais do VI Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg 2006)
影响因子: --
作者:
Jerônimo Pellegrini
通讯作者: Jerônimo Pellegrini
DOI: --
发表时间: 2016
期刊: --
影响因子: --
作者:
Santiago Torres-Arias;Anil Kumar Ammula;Reza Curtmola;Justin Cappos
通讯作者: Santiago Torres-Arias;Anil Kumar Ammula;Reza Curtmola;Justin Cappos
DOI: 10.1145/1242572.1242659
发表时间: 2007-05
期刊: --
影响因子: --
作者:
Yue Zhang;Jason I. Hong;L. Cranor
通讯作者: Yue Zhang;Jason I. Hong;L. Cranor