An empirical study of tactical vulnerabilities

An empirical study of tactical vulnerabilities
复制标题

DOI:
10.1016/j.jss.2018.10.030
复制
发表时间:
2019-03
期刊:
J. Syst. Softw.
影响因子:
--
通讯作者:
Joanna C. S. Santos;K. Tarrit;Adriana Sejfia;Mehdi Mirakhorli;M. Galster
Joanna C. S. Santos;K. Tarrit;Adriana Sejfia;Mehdi Mirakhorli;M. Galster
中科院分区:
其他
文献类型:
--
作者:
Joanna C. S. Santos;K. Tarrit;Adriana Sejfia;Mehdi Mirakhorli;M. Galster

文献摘要

被引文献

相似文献

架构安全策略(例如,授权、身份验证)用于实现利益相关者的安全需求。安全策略允许系统对攻击做出反应、抵抗、检测和恢复。在系统架构中采用这些策略的缺陷、安全策略的不正确实现或随着时间的推移策略实现的恶化可能会引入可被攻击者利用的严重漏洞。因此,在这项工作中,我们提出了通用体系结构弱点枚举(CAWE),这是一种源于安全策略的设计或实现的已知弱点的目录,这些弱点可能导致战术漏洞。我们将所有已知的软件弱点归类为与策略相关的和与策略无关的。这样,我们的CAWE目录列举了可能导致战术漏洞的安全体系结构中的常见弱点。从我们的CAWE目录中,我们发现了223种不同类型的战术漏洞。在这项工作中,我们还使用此目录研究了三个大型开源项目中的战术漏洞:Chrome、PHP和Thunderbird。在详细的分析中,我们确定了这些项目中最常见的漏洞类型。从这项研究中,我们观察到(I)不正确的输入验证和不正确的访问控制是Chromium、PHP和Thunderbird中最常见的漏洞类型,(Ii)“验证输入”和“授权参与者”是受这些战术漏洞影响最大的安全策略。此外,在对这些系统中的632个战术漏洞及其修复进行定性分析时,我们表征了这些漏洞的根本原因,并调查了每个系统的原始开发人员修复这些漏洞的方式。从这个定性分析中,我们发现了导致这些战术漏洞的44个不同的根本原因。这项研究的结果不仅显示了系统中的体系结构弱点如何造成严重的漏洞,而且还提供了由经验数据驱动的解决此类安全问题的建议。
Architectural security tactics (e.g., authorization, authentication) are used to achieve stakeholders’ security requirements. Security tactics allow the system to react, resist, detect and recover from attacks. Flaws in the adoption of these tactics into the system’s architecture, an incorrect implementation of security tactics, or deterioration of tactic implementations over time can introduce severe vulnerabilities that are exploitable by attackers. Therefore, in this work, we present theCommon Architectural Weakness Enumeration(CAWE), a catalog of known weaknesses rooted in the design or implementation of security tactics which can result in tactical vulnerabilities. We categorized all known software weaknesses as tactic-related and non-tactic related. This way, our CAWE catalog enumerates common weaknesses in a security architecture that can lead to tactical vulnerabilities. From our CAWE catalog, we found 223 different types of tactical vulnerabilities. In this work, we also used this catalog to study tactical vulnerabilities in three large-scale open source projects: Chromium, PHP, and Thunderbird. In a detailed analysis, we identified the most occurring vulnerability types on these projects. From this study we observed that (i) Improper Input Validation and Improper Access Control were the most occurring vulnerability types in Chromium, PHP and Thunderbird and (ii) “Validate Inputs” and “Authorize Actors” were the security tactics mostly affected by these tactical vulnerabilities. Moreover, in a qualitative analysis of 632 tactical vulnerabilities and their fixes in these systems, we characterized their root causes and investigated the way the original developers of each system fixed these vulnerabilities. From this qualitative analysis, we found 44 distinct root causes that lead to these tactical vulnerabilities. The results of this study not only show how architectural weaknesses in systems have created severe vulnerabilities, but also provide recommendations driven by empirical data for addressing such security problems.