USENIX Security2023Top-tier venue
Improving Logging to Reduce Permission Over-Granting Mistakes
Bingyu Shen, Tianyi Shan, Yuanyuan Zhou
Abstract
Access control configurations are gatekeepers to block unwelcome access to sensitive data. Unfortunately, system administrators (sysadmins) sometimes over-grant permissions when resolving unintended access-deny issues reported by legitimate users, which may open up security vulnerabilities for attackers. One of the primary reasons is that modern software does not provide informative logging to guide sysadmins to understand the reported problems. This paper makes one of the first attempts (to the best of our knowledge) to help developers improve log messages in order to help sysadmins correctly understand and fix access-deny issues without over-granting permissions. First, we conducted an observation study to understand the current practices of access-deny logging in the server software. Our study shows that many access-control program locations do not have any log messages; and a large percentage of existing log messages lack useful information to guide sysadmins to correctly understand and fix the issues. On top of our observations, we built SECLOG, which uses static analysis to automatically help developers find missing access-deny log locations and identify relevant information at the log location. We evaluated SECLOG with ten widely deployed server applications. Overall, SECLOG identified 380 new log statements for access-deny cases, and also enhanced 550 existing access-deny log messages with diagnostic information. We have reported 114 log statements to the developers of these applications, and so far 70 have been accepted into their main branches. We also conducted a user study with sysadmins (n=32) on six real-world access-deny issues. SECLOG can reduce the number of insecure fixes from 27 to 1, and also improve the diagnosis time by 64.2% on average. Correct and safe fix !" #%-.)4+534/(+(//5 6" #( +0'&(8 4/(-" 34/(-+(//5 9" :(.0;( 1$( userlist_file <0&)' (&1-= 10 %++07 %++ 4/(-/
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 97ac5dc8-4f86-4d60-95eb-5f6202b10b1eCited by top-tier papers2
- CASPR: Context-Aware Security Policy RecommendationLifang Xiao, Hanyu Wang, Aimin Yu, Lixin Zhao et al.NDSS 2025
- Multiview: Finding Blind Spots in Access-Deny Issues DiagnosisBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
Builds on2
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- Towards Continuous Access Control Validation and ForensicsChengcheng Xiang, Yudong Wu, Bingyu Shen, Mingyao Shen et al.CCS 2019 · 48 citations
Related papers
- Interpretable Vulnerability Detection ReportsCláudia Mamede, José Campos, Claire Le Goues, Rui AbreuASE 2025
- ConfLogger: Enhance Systems' Configuration Diagnosability through Configuration LoggingShiwen Shan, Yintong Huo, Yuxin Su, Zhining Wang et al.ICSE 2026
- Detecting Missing-Permission-Check Vulnerabilities in Distributed Cloud SystemsJie Lu, Haofeng Li, Chen Liu, Lian Li et al.CCS 2022 · 12 citations
- Forensic Analysis in Access Control: Foundations and a Case-Study from PracticeNahid Juma, Xiaowei Huang, Mahesh TripunitaraCCS 2020 · 2 citations
- Sentinel: Universal Analysis and Insight for Data SystemsBrad Glasbergen, Michael Abebe, Khuzaima Daudjee, Amit LeviVLDB 2020
