Is Modeling Access Control Worth It?
David A. Basin, Juan Guarnizo, Srdan Krstic, Hoang Nguyen Phuoc Bao, Martín Ochoa
摘要
Implementing access control policies is an error-prone task that can have severe consequences for the security of software applications. Model-driven approaches have been proposed in the literature and associated tools have been developed with the goal of reducing the complexity of this task and helping developers to produce secure software efficiently. Nevertheless, there is a lack of empirical data supporting the advantages of model-driven security approaches over code-centric approaches, which are the de-facto industry standard for software development. In this work, we compare the result of implementing the same functional and security requirements by multiple developer groups in the context of a security engineering graduate course. We thereby obtain evidence on the security and efficiency of a tool-based modeldriven approach to security from the literature compared to a direct implementation in a well-known, modern web-development framework. For example, the projects using model-driven development pass up to 50% more security tests on average with less development effort. Also, we observe that models are twice as concise as manual implementations, which improves system maintainability. CCS CONCEPTS • Software and its engineering → System modeling languages; • Security and privacy → Software security engineering; Access control.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper3
- Build It, Break It, Fix It: Contesting Secure DevelopmentAndrew Ruef, Michael W. Hicks, James Parker, Dave Levin 等CCS 2016 · 被引用 80 次
- Understanding the How and the Why: Exploring Secure Development Practices through a Course CompetitionKelsey R. Fulton, Daniel Votipka, Desiree Abrokwa, Michelle L. Mazurek 等CCS 2022 · 被引用 7 次
- Understanding security mistakes developers make: Qualitative analysis from Build It, Break It, Fix ItDaniel Votipka, Kelsey R. Fulton, James Parker, Matthew Hou 等USENIX Security 2020
相关 Paper
- MoFuzz: A Fuzzer Suite for Testing Model-Driven Software Engineering ToolsHoang Lam Nguyen, Nebras Nassar, Timo Kehrer, Lars GrunskeASE 2020 · 被引用 12 次
- STORM: Refinement Types for Secure Web ApplicationsNico Lehmann, Rose Kunkel, Jordan Brown, Jean Yang 等OSDI 2021 · 被引用 21 次
- Quantifying Permissiveness of Access Control PoliciesWilliam Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony 等ICSE 2022 · 被引用 15 次
- Do Users Write More Insecure Code with AI Assistants?Neil Perry, Megha Srivastava, Deepak Kumar, Dan BonehCCS 2023 · 被引用 150 次
- Less is More: Supporting Developers in Vulnerability Detection during Code ReviewLarissa Braz, Christian Aeberhard, Gül Çalikli, Alberto BacchelliICSE 2022 · 被引用 26 次
