Build It, Break It, Fix It: Contesting Secure Development

Build It, Break It, Fix It: Contesting Secure Development
复制标题

DOI:
10.1145/2976749.2978382
复制
发表时间:
2016-06
期刊:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Andrew Ruef;M. Hicks;James Parker;Dave Levin;Michelle L. Mazurek;Piotr (Peter) Mardziel
Andrew Ruef;M. Hicks;James Parker;Dave Levin;Michelle L. Mazurek;Piotr (Peter) Mardziel
中科院分区:
其他
文献类型:
--
作者:
Andrew Ruef;M. Hicks;James Parker;Dave Levin;Michelle L. Mazurek;Piotr (Peter) Mardziel

文献摘要

被引文献

相似文献

典型的安全竞赛侧重于破坏或减轻有缺陷的系统的影响。我们推出了Build-it,Break-it,Fix-it(BIBIFI)竞赛,旨在评估安全构建软件的能力,而不仅仅是破坏它。在BIBIFI中,团队构建指定的软件,目标是最大限度地提高正确性,性能和安全性。当团队试图破坏其他团队的提交时,测试后者。优胜者是从最好的建设者和最好的破坏者中选出的。BIBIFI的设计是开放式的-团队可以使用任何他们喜欢的语言,工具,流程等。因此,竞赛结果揭示了与成功构建安全软件和破解不安全软件相关的因素。在2015年,我们举办了三场比赛,共有116个团队参加,并解决了两个不同的编程问题。这些竞赛的定量分析发现,最有效的构建提交使用C/C++,但以其他静态类型语言编码的提交不太可能有安全缺陷;具有不同编程语言知识的构建团队也产生了更安全的代码。较短的课程与较好的成绩相关。同时也是成功的构建团队的突破团队在发现安全漏洞方面明显更好。
Typical security contests focus on breaking or mitigating the impact of buggy systems. We present the Build-it, Break-it, Fix-it (BIBIFI) contest, which aims to assess the ability to securely build software, not just break it. In BIBIFI, teams build specified software with the goal of maximizing correctness, performance, and security. The latter is tested when teams attempt to break other teams' submissions. Winners are chosen from among the best builders and the best breakers. BIBIFI was designed to be open-ended-teams can use any language, tool, process, etc. that they like. As such, contest outcomes shed light on factors that correlate with successfully building secure software and breaking insecure software. During 2015, we ran three contests involving a total of 116 teams and two different programming problems. Quantitative analysis from these contests found that the most efficient build-it submissions used C/C++, but submissions coded in other statically-typed languages were less likely to have a security flaw; build-it teams with diverse programming-language knowledge also produced more secure code. Shorter programs correlated with better scores. Break-it teams that were also successful build-it teams were significantly better at finding security bugs.