Inferring and securing software configurations using automated reasoning

Inferring and securing software configurations using automated reasoning
复制标题

使用自动推理来推断和保护软件配置

DOI:
10.1145/3368089.3417041
复制
发表时间:
2020
期刊:
Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering
影响因子:
--
通讯作者:
Gazzillo, Paul
Gazzillo, Paul
中科院分区:
--
文献类型:
--
作者:
Gazzillo, Paul

文献摘要

参考文献

被引文献

相似文献

软件可配置性为错误配置漏洞打开了大门,无效设置暴露了软件弱点。错误配置是十大最关键的安全风险之一,也是最常见的。本文设想了一个没有错误配置漏洞的世界,通过使用自动推理技术来推断和保护软件配置。然而,现实世界的软件往往缺乏明确的安全配置规范,依赖于用户的手动验证。现实世界的系统包括许多独立的高度可配置的软件组件,使得整个系统的可能配置空间非常巨大。为了实现我们的愿景,克服这些挑战,我们的目标是创建一个严格的定义配置规范,使用形式化的方法来机械化的推理和生成有效的配置,并开发算法来自动防止误配置。
Software configurability opens the door to misconfiguration vulnerabilities, invalid settings that expose software weaknesses. Misconfiguration is one the top ten most critical security risks and the most common. This paper envisions a world without misconfiguration vulnerabilities through the use of automated reasoning techniques to infer and secure software configurations. Real-world software, however, often lacks an explicit specification of secure configurations, relying on hand-validation by users. Real-world systems comprise many individual highly-configurable software components, making the space of possible configurations for the whole system enormous. To realize our vision and overcome these challenges, we aim to create a rigorous definition of configuration specifications, use formal methods to mechanize the inference and generation of valid configurations, and develop algorithms to automatically secure against misconfiguration.
基于云的 SMT 求解的子句共享和分区
DOI: 10.1007/978-3-319-46520-3_27
发表时间: 2016
期刊: 2004 IEEE Aerospace Conference Proceedings (IEEE Cat. No.04TH8720)
影响因子: --
作者:
Matteo Marescotti;A. Hyvärinen;N. Sharygina
通讯作者: N. Sharygina
Linux内核是一个软件产品线吗
DOI: --
发表时间: 2007
期刊:
影响因子: --
作者:
Julio Sincero;Horst Schirmeier;Wolfgang Schröder;O. Spinczyk;Friedrich
通讯作者: Friedrich
DOI: 10.1145/2642937.2642990
发表时间: 2014-09
期刊: Proceedings of the 29th ACM/IEEE International Conference on Automated Software Engineering
影响因子: --
作者:
Iago Abal;Claus Brabrand;A. Wąsowski
通讯作者: Iago Abal;Claus Brabrand;A. Wąsowski