Improving Logging to Reduce Permission Over-Granting Mistakes
Bingyu Shen, Tianyi Shan, Yuanyuan Zhou
摘要
Access control configurations are gatekeepers to block unwelcome access to sensitive data. Unfortunately, system administrators (sysadmins) sometimes over-grant permissions when resolving unintended access-deny issues reported by legitimate users, which may open up security vulnerabilities for attackers. One of the primary reasons is that modern software does not provide informative logging to guide sysadmins to understand the reported problems. This paper makes one of the first attempts (to the best of our knowledge) to help developers improve log messages in order to help sysadmins correctly understand and fix access-deny issues without over-granting permissions. First, we conducted an observation study to understand the current practices of access-deny logging in the server software. Our study shows that many access-control program locations do not have any log messages; and a large percentage of existing log messages lack useful information to guide sysadmins to correctly understand and fix the issues. On top of our observations, we built SECLOG, which uses static analysis to automatically help developers find missing access-deny log locations and identify relevant information at the log location. We evaluated SECLOG with ten widely deployed server applications. Overall, SECLOG identified 380 new log statements for access-deny cases, and also enhanced 550 existing access-deny log messages with diagnostic information. We have reported 114 log statements to the developers of these applications, and so far 70 have been accepted into their main branches. We also conducted a user study with sysadmins (n=32) on six real-world access-deny issues. SECLOG can reduce the number of insecure fixes from 27 to 1, and also improve the diagnosis time by 64.2% on average. Correct and safe fix !" #%-.)4+534/(+(//5 6" #( +0'&(8 4/(-" 34/(-+(//5 9" :(.0;( 1$( userlist_file <0&)' (&1-= 10 %++07 %++ 4/(-/
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- CASPR: Context-Aware Security Policy RecommendationLifang Xiao, Hanyu Wang, Aimin Yu, Lixin Zhao 等NDSS 2025
- Multiview: Finding Blind Spots in Access-Deny Issues DiagnosisBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
它引用的顶会 Paper2
相关 Paper
- Interpretable Vulnerability Detection ReportsCláudia Mamede, José Campos, Claire Le Goues, Rui AbreuASE 2025
- ConfLogger: Enhance Systems' Configuration Diagnosability through Configuration LoggingShiwen Shan, Yintong Huo, Yuxin Su, Zhining Wang 等ICSE 2026
- Detecting Missing-Permission-Check Vulnerabilities in Distributed Cloud SystemsJie Lu, Haofeng Li, Chen Liu, Lian Li 等CCS 2022 · 被引用 12 次
- Forensic Analysis in Access Control: Foundations and a Case-Study from PracticeNahid Juma, Xiaowei Huang, Mahesh TripunitaraCCS 2020 · 被引用 2 次
- Sentinel: Universal Analysis and Insight for Data SystemsBrad Glasbergen, Michael Abebe, Khuzaima Daudjee, Amit LeviVLDB 2020
