Continuous Compliance
Martin Kellogg, Martin Schäf, Serdar Tasiran, Michael D. Ernst
摘要
Vendors who wish to provide software or services to large corporations and governments must often obtain numerous certificates of compliance. Each certificate asserts that the software satisfies a compliance regime, like SOC or the PCI DSS, to protect the privacy and security of sensitive data. The industry standard for obtaining a compliance certificate is an auditor manually auditing source code. This approach is expensive, error-prone, partial, and prone to regressions. We propose continuous compliance to guarantee that the codebase stays compliant on each code change using lightweight verification tools. Continuous compliance increases assurance and reduces costs. Continuous compliance is applicable to any source-code compliance requirement. To illustrate our approach, we built verification tools for five common audit controls related to data security: cryptographically unsafe algorithms must not be used, keys must be at least 256 bits long, credentials must not be hard-coded into program text, HTTPS must always be used instead of HTTP, and cloud data stores must not be world-readable. We evaluated our approach in three ways. ( 1 ) We applied our tools to over 5 million lines of open-source software. (2) We compared our tools to other publicly-available tools for detecting misuses of encryption on a previously-published benchmark, finding that only ours are suitable for continuous compliance. (3) We deployed a continuous compliance process at AWS, a large cloudservices company: we integrated verification tools into the compliance process (including auditors accepting their output as evidence) and ran them on over 68 million lines of code. Our tools and the data for the former two evaluations are publicly available. CCS CONCEPTS • Software and its engineering → Software verification; Automated static analysis; Data types and structures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Pluggable Type Inference for FreeMartin Kellogg, Daniel Daskiewicz, Loi Ngo Duc Nguyen, Muyeed Ahmed 等ASE 2023 · 被引用 4 次
- Static Program Reduction via Type-Directed SlicingLoi Ngo Duc Nguyen, Tahiatul Islam, Theron Wang, Sam Lenz 等ISSTA 2025
- Verifying the Option Type with Rely-Guarantee ReasoningJames Yoo, Michael D. Ernst, René JustASE 2024
它引用的顶会 Paper3
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon 等CCS 2019 · 被引用 159 次
- Security Certification in Payment Card Industry: Testbeds, Measurements, and RecommendationsSazzadur Rahaman, Gang Wang, Danfeng Daphne YaoCCS 2019 · 被引用 31 次
- Verifying object constructionMartin Kellogg, Manli Ran, Manu Sridharan, Martin Schäf 等ICSE 2020 · 被引用 10 次
相关 Paper
- C-Verifier: Understanding and Formally Verifying Cross-Service Flaws in AWS CognitoZhen Chen, Ze Jin, Le Gong, Kexin Chen 等S&P 2026
- Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper)Mingjie Shen, Akul Abhilash Pillai, Brian A. Yuan, James C. Davis 等ISSTA 2025 · 被引用 1 次
- Growlithe: A Developer-Centric Compliance Tool for Serverless ApplicationsPraveen Gupta, Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad 等S&P 2025
- Formally Verified Cloud-Scale AuthorizationAleks Chakarov, Jaco Geldenhuys, Matthew Heck, Michael Hicks 等ICSE 2025 · 被引用 1 次
- Continuous Intrusion: Characterizing the Security of Continuous Integration ServicesYacong Gu, Lingyun Ying, Huajun Chai, Chu Qiao 等S&P 2023
