kirancodes.me
To Proof Maintenance & Beyond!

A security policy oracle: detecting security holes using multiple API implementations

Varun Srivastava, Michael D. Bond, Kathryn S. McKinley, Vitaly Shmatikov

Abstract

Even experienced developers struggle to implement security policies correctly. For example, despite 15 years of development, standard Java libraries still suffer from missing and incorrectly applied permission checks, which enable untrusted applications to execute native calls or modify private class variables without authorization. Previous techniques for static verification of authorization enforcement rely on manually specified policies or attempt to infer the policy by code-mining. Neither approach guarantees that the policy used for verification is correct.

Related papers