kirancodes.me
To Proof Maintenance & Beyond!

Mining Security-Sensitive Operations in Legacy Code Using Concept Analysis

Vinod Ganapathy, Dave King, Trent Jaeger, Somesh Jha

Abstract

This paper presents an approach to statically retrofit legacy servers with mechanisms for authorization policy enforcement. The approach is based upon the observation that security-sensitive operations performed by a server are characterized by idiomatic resource manipulations, called fingerprints. Candidate fingerprints are automatically mined by clustering resource manipulations using concept analysis. These fingerprints are then used to identify security-sensitive operations performed by the server. Case studies with three real-world servers show that the approach can be used to identify security-sensitive operations with a few hours of manual effort and modest domain knowledge.

BibTeX
@inproceedings{Ganapathy-al:ICSE07,
  author    = {Vinod Ganapathy and
               Dave King and
               Trent Jaeger and
               Somesh Jha},
  title     = {Mining {Security-Sensitive} Operations in Legacy Code Using Concept Analysis},
  booktitle = {ICSE},
  pages     = {458--467},
  publisher = {{IEEE} Computer Society},
  year      = {2007},
}

Related papers