USENIX ATC2020顶会
PracExtractor: Extracting Configuration Good Practices from Manuals to Detect Server Misconfigurations
Chengcheng Xiang, Haochen Huang, Andrew Yoo, Yuanyuan Zhou, Shankar Pasupathy
摘要
Configuration has become ever so complex and error-prone in today's server software. To mitigate this problem, software vendors provide user manuals to guide system admins on configuring their systems. Usually, manuals describe not only the meaning of configuration parameters but also good practice recommendations on how to configure certain parameters. Unfortunately, manuals usually also have a large number of pages, which are time-consuming for humans to read and understand. Therefore, system admins often do not refer to manuals but rely on their own guesswork or unreliable sources when setting up systems, which can lead to configuration errors and system failures.
To understand the characteristics of configuration recommendations in user manuals, this paper first collected and studied 261 recommendations from the manuals of six large open-source systems. Our study shows that 60% of the studied recommendations describe specific and checkable specifications instead of merely general guidance. Moreover, almost all (97%) of such specifications have not been checked in the systems' source code, and 61% of them are not equivalent to the default settings. This implies that additional checking is needed to ensure the recommendations are correctly applied.
Based on our characteristic study, we build a tool called PracExtractor, which employs Natural Language Processing (NLP) techniques to automatically extract configuration recommendations from software manuals, converts them into specifications, and then uses the generated specifications to detect violations in system admins' configuration settings. We evaluate PracExtractor with twelve widely-deployed software systems, including one large commercial system from a public company. In total, PracExtractor automatically extracts 338 recommendations and generates 173 specifications with reasonable accuracy. With these generated specifications, PracExtractor detects 1423 good practice violations from open-source docker images. To this day, we have reported 325 violations and have got 47 of them confirmed as real configuration issues by admins from different organizations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Test-case prioritization for configuration testingRunxiang Cheng, Lingming Zhang, Darko Marinov, Tianyin XuISSTA 2021 · 被引用 34 次
- Static detection of silent misconfigurations with deep interaction analysisJialu Zhang, Ruzica Piskac, Ennan Zhai, Tianyin XuOOPSLA 2021 · 被引用 30 次
- An Evolutionary Study of Configuration Design and Implementation in Cloud SystemsYuanliang Zhang, Haochen He, Owolabi Legunsen, Shanshan Li 等ICSE 2021 · 被引用 19 次
- Multi-Intention-Aware Configuration Selection for Performance TuningHaochen He, Zhouyang Jia, Shanshan Li, Yue Yu 等ICSE 2022 · 被引用 11 次
- Finding heterogeneous-unsafe configuration parameters in cloud systemsSixiang Ma, Fang Zhou, Michael D. Bond, Yang WangEuroSys 2021 · 被引用 8 次
它引用的顶会 Paper1
相关 Paper
- Automated Implementation of Windows-related Security-Configuration GuidesPatrick Stöckle, Bernd Grobauer, Alexander PretschnerASE 2020 · 被引用 8 次
- On Prescription or Off Prescription? An Empirical Study of Community-Prescribed Security Configurations for KubernetesShazibul Islam Shamim, Hanyang Hu, Akond RahmanICSE 2025 · 被引用 4 次
- Configuration smells in continuous delivery pipelines: a linter and a six-month study on GitLabCarmine Vassallo, Sebastian Proksch, Anna Jancso, Harald C. Gall 等FSE 2020 · 被引用 43 次
- Learning Patterns in ConfigurationRanjita Bhagwan, Sonu Mehta, Arjun Radhakrishna, Sahil GargASE 2021 · 被引用 11 次
- DiagConfig: Configuration Diagnosis of Performance Violations in Configurable Software SystemsZhiming Chen, Pengfei Chen, Peipei Wang, Guangba Yu 等FSE 2023 · 被引用 9 次
