Finding Security Bugs in Web Applications using a Catalog of Access Control Patterns
Name
jnear-icse16.pdf
Size
1.2 MB
Format
Adobe PDF
Checksum (MD5)
e00b24b4c542218a65f5dacb991b53af
Author(s) •
Near, Joseph Paul
Jackson, Daniel
Date Issued
May 2016
Journal
Proceedings of the 38th International Conference on Software Engineering
Publisher
Association for Computing Machinery (ACM)
Citation
Near, Joseph P., and Daniel Jackson. "Finding Security Bugs in Web Applications using a Catalog of Access Control Patterns." 38th International Conference on Software Engineering (May 2016).
Version
Author's final manuscript
Abstract
We propose a specification-free technique for finding missing security checks in web applications using a catalog of access control patterns in which each pattern models a common access control use case. Our implementation, Space, checks that every data exposure allowed by an application's code matches an allowed exposure from a security pattern in our catalog. The only user-provided input is a mapping from application types to the types of the catalog; the rest of the process is entirely automatic. In an evaluation on the 50 most watched Ruby on Rails applications on Github, Space reported 33 possible bug--|23 previously unknown security bugs, and 10 false positives.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike
Persistent DSpace Link
DOI of Published Version
http://2016.icse.cs.txstate.edu/technical-research