Towards supporting software assurance assessments by detecting security patterns

Towards supporting software assurance assessments by detecting security patterns
复制标题

通过检测安全模式来支持软件保障评估

DOI:
10.1007/s11219-019-09492-z
复制
发表时间:
2020
影响因子:
1.9
通讯作者:
Karsten
Karsten
中科院分区:
计算机科学4区
文献类型:
--
作者:
Michaela ;Karsten

文献摘要

参考文献

相似文献

今天,存在许多试图找到Android应用程序中可能的漏洞的工具,例如,FlowDroid、Fortify或AppScan。然而,所有这些工具的目的都是检测漏洞或(有时)污染流,并向审查人员展示所分析的Android应用程序中检测到的可能问题。这些工具都不支持在代码中识别已实现的安全功能,尽管这方面也与开发人员和评审人员相关。为了解决这个问题,我们提出了一个程序理解方法的基础上连接对象进程图(COPG)包含交互对象描述的安全模式在本文中。我们的方法的可行性进行了定性评估与25个安全关键的Android应用程序从Google Play与近700万行代码。我们目前支持17种安全模式变体,在应用程序中正确检测到约199个模式实例。我们还定义了一个非平凡的,安全关键的Android应用程序,它也可以用于其他安全分析任务的基础上的静态分析框架Soot的基准。通过这个基准,我们的分析产生了99%的准确率和80%的召回率。最后,我们与SAFECode组织的六位软件安全专家讨论了我们的方法和开发的工具,以获得更多的反馈。
Today, many tools exist that attempt to find possible vulnerabilities in Android applications, e.g., FlowDroid, Fortify, or AppScan. However, all these tools aim to detect vulnerabilities or (sometimes) tainted flows and present the reviewer detected possible issues of an analyzed Android application. None of these tools supports the identification of implemented security features in code, although this aspect is also relevant to developers as well as reviewers. To address this open problem, we present a program comprehension approach based on connected object process graphs (COPGs) containing interacting objects described by security patterns in this paper. The feasibility of our approach is evaluated qualitatively with 25 security-critical Android applications from Google Play with almost 7 million lines of code. We currently support 17 security pattern variants with about 199 correctly detected pattern instances in the apps. We also define a benchmark of non-trivial, security-critical Android apps, which can also be used for other security analysis tasks based on the static analysis framework Soot. With this benchmark, our analysis yields a precision of 99% and a recall of 80%. Finally, we discussed our approach and the developed tool with six software security experts from the SAFECode organization to obtain additional feedback.
带有指针的程序的静态对象跟踪提取
DOI: --
发表时间: 2005
影响因子: 3.5
作者:
T. Eisenbarth;R. Koschke;G. Vogel
通讯作者: G. Vogel
DOI: --
发表时间: 2005
期刊: Conference on Object-Oriented Programming Systems, Languages, and Applications
影响因子: --
作者:
M. Hafiz
通讯作者: M. Hafiz
SAFECode 白皮书:安全软件开发的基本实践第二版
DOI: --
发表时间: 2014
期刊: Information Security Solutions Europe
影响因子: --
作者:
Stacy Simpson
通讯作者: Stacy Simpson
通过逆向工程检测代码中的安全模式
DOI: --
发表时间: 2007
期刊:
影响因子: --
作者:
M. VanHilst;E. Fernández
通讯作者: E. Fernández
使用有序矩阵匹配进行安全模式检测
DOI: --
发表时间: 2017
期刊: International Conference on Software Security and Assurance
影响因子: --
作者:
A. Alvi;Mohammad Zulkernine
通讯作者: Mohammad Zulkernine