On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software Vulnerabilities

On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software Vulnerabilities
复制标题

DOI:
--
复制
发表时间:
2016
期刊:
--
影响因子:
--
通讯作者:
Santiago Torres-Arias;Anil Kumar Ammula;Reza Curtmola;Justin Cappos
Santiago Torres-Arias;Anil Kumar Ammula;Reza Curtmola;Justin Cappos
中科院分区:
其他
文献类型:
--
作者:
Santiago Torres-Arias;Anil Kumar Ammula;Reza Curtmola;Justin Cappos

文献摘要

被引文献

相似文献

元数据操作攻击代表了一种针对版本控制系统(如流行的Git)的新威胁类。这种类型的攻击为不同的开发人员提供了不一致的存储库状态视图,并欺骗他们执行意想不到的操作,通常会带来负面后果。其中包括省略安全补丁,将未经测试的代码合并到生产分支中,甚至无意中安装了包含已知漏洞的软件。更糟糕的是,这些攻击本质上是微妙的,执行后不会留下任何痕迹。我们提出了一种防御方案,通过维护相关开发人员操作的加密签名日志来减轻这些攻击。通过在采取操作的特定时间记录存储库的状态,开发人员可以获得共享的历史记录,因此很容易检测到异常情况。我们的方案原型实现可以立即部署,因为它是向后兼容的,并且为Git用户保留了当前的工作流程和用例。评估表明,该防御增加了适度的开销,同时提供了明显更强的安全性。我们对这些攻击进行了负责任的披露,并正在与Git社区合作,在即将发布的Git版本中修复这些问题。
Metadata manipulation attacks represent a new threat class directed against Version Control Systems, such as the popular Git. This type of attack provides inconsistent views of a repository state to different developers, and deceives them into performing unintended operations with often negative consequences. These include omitting security patches, merging untested code into a production branch, and even inadvertently installing software containing known vulnerabilities. To make matters worse, the attacks are subtle by nature and leave no trace after being executed. We propose a defense scheme that mitigates these attacks by maintaining a cryptographically-signed log of relevant developer actions. By documenting the state of the repository at a particular time when an action is taken, developers are given a shared history, so irregularities are easily detected. Our prototype implementation of the scheme can be deployed immediately as it is backwards compatible and preserves current workflows and use cases for Git users. An evaluation shows that the defense adds a modest overhead while offering sig-nificantly stronger security. We performed responsible disclosure of the attacks and are working with the Git community to fix these issues in an upcoming version of Git.