Exploring and enforcing security guarantees via program dependence graphs

Exploring and enforcing security guarantees via program dependence graphs
复制标题

DOI:
10.1145/2737924.2737957
复制
发表时间:
2015-06
期刊:
Proceedings of the 36th ACM SIGPLAN Conference on Programming Language Design and Implementation
影响因子:
--
通讯作者:
Andrew Johnson;Lucas Waye;Scott Moore;Stephen Chong
Andrew Johnson;Lucas Waye;Scott Moore;Stephen Chong
中科院分区:
其他
文献类型:
--
作者:
Andrew Johnson;Lucas Waye;Scott Moore;Stephen Chong

文献摘要

被引文献

相似文献

我们提出了Pidgin,这是一种程序分析和理解工具,能够指定和执行精确的特定于应用程序的信息安全保证。Pidgin还允许开发人员交互地探索其应用程序中的信息流,以制定政策和调查反例。Pidgin将精确捕获整个应用程序中的信息流的程序依赖图(PDG)与定制的PDG查询语言结合在一起。查询表示有关PDG中路径的属性;因为PDG中的路径对应于应用程序中的信息流,所以查询可用于指定全局安全策略。Pidgin是可扩展的。为33万行Java应用程序生成PDG需要90秒,检查该PDG上的策略需要不到14秒。该查询语言具有表现力,支持一大类精确的、特定于应用程序的安全保证。策略独立于代码,不会干扰测试或开发,并且可以用于安全回归测试。我们描述了Pidgin的设计和实现,并报告了它的使用情况:(1)探索遗留程序中的信息安全保证;(2)在应用程序开发的同时开发和修改安全策略;(3)基于已知漏洞开发策略。
We present PIDGIN, a program analysis and understanding tool that enables the specification and enforcement of precise application-specific information security guarantees. PIDGIN also allows developers to interactively explore the information flows in their applications to develop policies and investigate counter-examples. PIDGIN combines program dependence graphs (PDGs), which precisely capture the information flows in a whole application, with a custom PDG query language. Queries express properties about the paths in the PDG; because paths in the PDG correspond to information flows in the application, queries can be used to specify global security policies. PIDGIN is scalable. Generating a PDG for a 330k line Java application takes 90 seconds, and checking a policy on that PDG takes under 14 seconds. The query language is expressive, supporting a large class of precise, application-specific security guarantees. Policies are separate from the code and do not interfere with testing or development, and can be used for security regression testing. We describe the design and implementation of PIDGIN and report on using it: (1) to explore information security guarantees in legacy programs; (2) to develop and modify security policies concurrently with application development; and (3) to develop policies based on known vulnerabilities.