DC Field | Value | Language |
---|---|---|
dc.contributor.author | Lu, Yi | ko |
dc.contributor.author | Bae, Sora | ko |
dc.contributor.author | Krishnan, Padmanabhan | ko |
dc.contributor.author | Raghavendra, KR | ko |
dc.date.accessioned | 2023-09-07T10:00:34Z | - |
dc.date.available | 2023-09-07T10:00:34Z | - |
dc.date.created | 2023-09-07 | - |
dc.date.issued | 2017-05 | - |
dc.identifier.citation | 2017 IEEE Security and Privacy Workshops (SPW), pp.102 - 109 | - |
dc.identifier.issn | 2639-7862 | - |
dc.identifier.uri | http://hdl.handle.net/10203/312329 | - |
dc.description.abstract | Programming languages such as Java and C# execute code with different levels of trust in the same process, and rely on an access control model with fine-grained permissions to protect program code. Permissions are checked programmatically, and rely on programmer discipline. This can lead to subtle errors. To enable automatic security analysis about unauthorised access or information flow, it is necessary to reason about security-sensitive entities in libraries that must be protected by appropriate sanitisation/declassification via permission checks. Unfortunately, security-sensitive entities are not clearly identified. In this paper, we investigate security-sensitive entities used in Java-like languages, and develop a static program analysis technique to identify them in large codebases by analysing the patterns of permission checks. Although the technique is generic, our focus is on Java where checkPermission calls are used to guard potential security-sensitive entities. Our inference analysis uses two parameters called proximity and coverage to reduce false-positive and false-negative reports. The usefulness of the analysis is illustrated by the results obtained while checking the OpenJDK7-b147 for conformance to Java Secure Coding Guidelines that relate to the confidentiality and integrity requirements. | - |
dc.language | English | - |
dc.publisher | IEEE | - |
dc.title | Inference of Security-Sensitive Entities in Libraries | - |
dc.type | Conference | - |
dc.identifier.wosid | 000852904100013 | - |
dc.identifier.scopusid | 2-s2.0-85048938488 | - |
dc.type.rims | CONF | - |
dc.citation.beginningpage | 102 | - |
dc.citation.endingpage | 109 | - |
dc.citation.publicationname | 2017 IEEE Security and Privacy Workshops (SPW) | - |
dc.identifier.conferencecountry | US | - |
dc.identifier.conferencelocation | San Jose, CA | - |
dc.identifier.doi | 10.1109/spw.2017.26 | - |
dc.contributor.nonIdAuthor | Lu, Yi | - |
dc.contributor.nonIdAuthor | Krishnan, Padmanabhan | - |
dc.contributor.nonIdAuthor | Raghavendra, KR | - |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.