Understanding security mistakes developers make: Qualitative analysis from Build It, Break It, Fix It

Understanding security mistakes developers make: Qualitative analysis from Build It, Break It, Fix It
复制标题

DOI:
--
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Daniel Votipka;Kelsey R. Fulton;James Parker;Matthew Hou;Michelle L. Mazurek;M. Hicks
Daniel Votipka;Kelsey R. Fulton;James Parker;Matthew Hou;Michelle L. Mazurek;M. Hicks
中科院分区:
其他
文献类型:
--
作者:
Daniel Votipka;Kelsey R. Fulton;James Parker;Matthew Hou;Michelle L. Mazurek;M. Hicks

文献摘要

被引文献

相似文献

安全软件开发是一项具有挑战性的任务,需要考虑许多可能的威胁和缓解措施。本文研究了程序员如何以及为什么,尽管基线的安全经验,使安全相关的错误。为了做到这一点,我们对94个提交给安全编程竞赛的作品进行了深入分析,该竞赛旨在模拟现实世界的约束:正确性,性能和安全性。除了编写安全代码外,参与者还被要求搜索其他团队程序中的漏洞;在我们考虑的提交中,团队总共提交了866个漏洞。在六个月的密集时间里,我们使用迭代开放编码来手动但系统地描述每个提交的项目和漏洞(包括我们自己艾德的漏洞)。我们根据类型、允许的攻击者控制和易受攻击性以及根据安全实施策略的项目对漏洞进行了标记。出现了几种模式。例如,简单的错误最不常见:只有21%的项目引入了这样的错误。相反,由于对安全概念的误解而产生的漏洞更为常见,出现在78%的项目中。我们的研究结果对改进安全编程API、API文档、漏洞发现工具和安全教育具有重要意义。
Secure software development is a challenging task requiring consideration of many possible threats and mitigations. This paper investigates how and why programmers, despite a baseline of security experience, make security-relevant errors. To do this, we conducted an in-depth analysis of 94 submissions to a secure-programming contest designed to mimic real-world constraints: correctness, performance, and security. In addition to writing secure code, participants were asked to search for vulnerabilities in other teams’ programs; in total, teams submitted 866 exploits against the submissions we considered. Over an intensive six-month period, we used iterative open coding to manually, but systematically, characterize each submitted project and vulnerability (including vulnerabilities we identified ourselves). We labeled vulnerabilities by type, attacker control allowed, and ease of exploitation, and projects according to security implementation strategy. Several patterns emerged. For example, simple mistakes were least common: only 21% of projects introduced such an error. Conversely, vulnerabilities arising from a misunderstanding of security concepts were significantly more common, appearing in 78% of projects. Our results have implications for improving secure-programming APIs, API documentation, vulnerability-finding tools, and security education.