Show simple item record

dc.contributor.authorNear, Joseph Paul
dc.contributor.authorJackson, Daniel
dc.date.accessioned2016-04-20T19:02:36Z
dc.date.available2016-04-20T19:02:36Z
dc.date.issued2016-05
dc.identifier.isbn978-1-4503-3900-1
dc.identifier.urihttp://hdl.handle.net/1721.1/102281
dc.description.abstractWe propose a specification-free technique for finding missing security checks in web applications using a catalog of access control patterns in which each pattern models a common access control use case. Our implementation, Space, checks that every data exposure allowed by an application's code matches an allowed exposure from a security pattern in our catalog. The only user-provided input is a mapping from application types to the types of the catalog; the rest of the process is entirely automatic. In an evaluation on the 50 most watched Ruby on Rails applications on Github, Space reported 33 possible bug--|23 previously unknown security bugs, and 10 false positives.en_US
dc.description.sponsorshipNational Science Foundation (U.S.) (Grant 0707612)en_US
dc.language.isoen_US
dc.publisherAssociation for Computing Machinery (ACM)en_US
dc.relation.isversionofhttp://2016.icse.cs.txstate.edu/technical-researchen_US
dc.rightsCreative Commons Attribution-Noncommercial-Share Alikeen_US
dc.rights.urihttp://creativecommons.org/licenses/by-nc-sa/4.0/en_US
dc.sourceJacksonen_US
dc.titleFinding Security Bugs in Web Applications using a Catalog of Access Control Patternsen_US
dc.typeArticleen_US
dc.identifier.citationNear, Joseph P., and Daniel Jackson. "Finding Security Bugs in Web Applications using a Catalog of Access Control Patterns." 38th International Conference on Software Engineering (May 2016).en_US
dc.contributor.departmentMassachusetts Institute of Technology. Department of Electrical Engineering and Computer Scienceen_US
dc.contributor.approverJackson, Danielen_US
dc.contributor.mitauthorJackson, Danielen_US
dc.relation.journalProceedings of the 38th International Conference on Software Engineeringen_US
dc.eprint.versionAuthor's final manuscripten_US
dc.type.urihttp://purl.org/eprint/type/ConferencePaperen_US
eprint.statushttp://purl.org/eprint/status/NonPeerRevieweden_US
dspace.orderedauthorsNear, Joseph P.; Jackson, Danielen_US
dc.identifier.orcidhttps://orcid.org/0000-0003-4864-078X
mit.licenseOPEN_ACCESS_POLICYen_US
mit.metadata.statusComplete


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record