arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

安全不仅仅是库调用:安全特性如何在代码中体现

Security Is More Than a Library Call: How Security Features Live in Code

Kevin Hermann, Sven Peldszus, Thorsten Berger

arXiv 2610.06132首次发表:更新:

发表机构

Ruhr University Bochum; Chalmers | University of Gothenburg(鲁尔大学波鸿分校; 查尔姆斯理工大学|哥德堡大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过挖掘9个大型开源Java系统,发现安全特性在代码中远非简单库调用,而是规模大、分散且相互缠绕,需大量集成代码。

AI 中文摘要

实现安全特性——即保护敏感数据或防止攻击者恶意行为的功能——对于确保软件系统的安全性和完整性至关重要。正确实现访问控制、密码学或其他安全特性具有挑战性,因为它们需要大量的领域专业知识、仔细的设计和自定义实现,以便将其集成到软件系统中。先前的工作通过调查、访谈和实验深入研究了安全意识、感知、实践和专业知识。虽然这些研究表明安全特性的实现通常得到安全库和框架的支持,但它们也表明开发者很少是安全专家,并且在使用这些库和框架时会犯错误,从而在软件中引入漏洞。尽管对安全实践和开发者行为有如此广泛的了解,我们仍然缺乏对安全特性在整个软件系统中如何在代码层面实际体现的全面理解。我们通过一项挖掘研究来弥补这一差距,该研究针对9个流行且大型的开源Java系统。我们手动检查了19,121个文件中的2,127,761行代码,识别并标注了183,395行实现561个安全特性的代码,这些特性对应于我们分类法中的54个安全特性。我们分析了所识别安全特性的特征,例如它们的大小、分散性、缠绕性、常见实现模式以及内部和外部功能的使用。我们的研究结果表明,安全特性远不止是对外部库的简单调用。安全特性(如访问控制)可能规模庞大,分散在整个代码库中,并且经常相互缠绕。外部安全库被普遍使用,但需要大量代码进行集成。

英文摘要

Implementing security features---functionalities that protect sensitive data or prevent malicious actions by attackers---is important for ensuring the security and integrity of software systems. Correctly implementing access control, cryptography, or other security features is challenging as they require substantial domain expertise, careful design, and custom implementation to integrate them within the software system. Previous work has thoroughly studied security awareness, perception, practices, and expertise via surveys, interviews, and experiments. While they have shown that the implementation of security features are often supported by security libraries and frameworks, they have also shown that developers rarely are security experts, and make mistakes that introduce vulnerabilities into software when using them. Despite this extensive knowledge of security practices and developer behavior, we still lack a comprehensive understanding of how security features actually manifest at the code level across full software systems. We close this gap by conducting a mining study of security features in 9 popular and large open-source Java systems. We manually inspected 2,127,761 lines of code across 19,121 files, identifying and annotating 183,395 lines implementing 561 security features corresponding to 54 security features in our taxonomy. We analyzed the characteristics of the identified security features, such as their size, scattering, tangling, common implementation patterns, and the use of internal and external functionalities. Our findings show that security features are far more than mere calls to external libraries. Security features, such as access control, can grow large in size, scatter across the whole codebase, and frequently tangle with each other. External security libraries are commonly used, but they require substantial amounts of code for integration.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑