USENIX Security2023Top-tier venue
Multiview: Finding Blind Spots in Access-Deny Issues Diagnosis
Bingyu Shen, Tianyi Shan, Yuanyuan Zhou
Abstract
Access-deny issues are hard to fix because it implies both availability and security requirements. On one hand, system administrators (sysadmins) need to make a change quickly to enable legitimate access. On the other hand, sysadmins need to make sure the change does not allow excessive access. Fulfilling the second requirement on security is especially challenging because it highly requires the sysadmins' knowledge of the system environments and security context. Blind spots in knowledge and system settings may hinder sysadmins from finding solutions that align with the security context. Insecure fixes can over-grant permissions, which may only get noticed after the security vulnerability gets exploited. This paper aims to help sysadmins reduce blind spots in diagnosis by providing multiple directions to resolve accessdeny issues. We propose a system, called Multiview, that automatically mutates the configurations to explore possible directions to fix the access-deny issue and lets the configuration changes in each direction grant as few permissions as possible. Multiview provides a detailed diagnosis report, including access-control configurations that are related to the denial, possible configuration changes in different directions to allow the request, as well as the impact on the accesscontrol state of the entire system. We conducted a user study to evaluate Multiview with 20 participants on five real-world access-deny issues. Multiview can reduce the percentage of insecure fixes from 44.0% to 2.0% and reduce the diagnosis time by 62.0% on average. We also evaluated Multiview on 112 real-world failure cases from eight different systems and server applications, and it can successfully diagnose 89 of them. Multiview accurately identifies the failure-causing configurations and provides possible directions to each access-deny issue within one minute.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7a6ae679-00d2-4a92-b238-3ad0fc2615eeCited by top-tier papers2
- Erebus: Access Control for Augmented Reality SystemsYoonsang Kim, Sanket Goutam, Amir Rahmati, Arie E. KaufmanUSENIX Security 2023
- Effective Bug Detection with Unused DefinitionsLi Zhong, Chengcheng Xiang, Haochen Huang, Bingyu Shen et al.EuroSys 2024
Builds on5
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- Towards Continuous Access Control Validation and ForensicsChengcheng Xiang, Yudong Wu, Bingyu Shen, Mingyao Shen et al.CCS 2019 · 48 citations
- Can Systems Explain Permissions Better? Understanding Users' Misperceptions under Smartphone Runtime Permission ModelBingyu Shen, Lili Wei, Chengcheng Xiang, Yudong Wu et al.USENIX Security 2021 · 45 citations
- Protecting Data Integrity of Web Applications with Database Constraints Inferred from Application CodeHaochen Huang, Bingyu Shen, Li Zhong, Yuanyuan ZhouASPLOS 2023 · 16 citations
- Improving Logging to Reduce Permission Over-Granting MistakesBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
Related papers
- "Technically speaking I'm at the top of the hierarchy": How System Administrators Think About PowerLydia Weinberger, Carolin Lämmle, Andreas Hammer, Christian Eichenmüller et al.CHI 2026 · 1 citation
- CASPR: Context-Aware Security Policy RecommendationLifang Xiao, Hanyu Wang, Aimin Yu, Lixin Zhao et al.NDSS 2025
- On Debugging the Performance of Configurable Software Systems: Developer Needs and Tailored Tool SupportMiguel Velez, Pooyan Jamshidi, Norbert Siegmund, Sven Apel et al.ICSE 2022 · 21 citations
- ACHyb: a hybrid analysis approach to detect kernel access control vulnerabilitiesYang Hu, Wenxi Wang, Casen Hunger, Riley Wood et al.FSE 2021 · 6 citations
- DiagConfig: Configuration Diagnosis of Performance Violations in Configurable Software SystemsZhiming Chen, Pengfei Chen, Peipei Wang, Guangba Yu et al.FSE 2023 · 9 citations
