A Grounded Theory Based Approach to Characterize Software Attack Surfaces
Sara Moshtari, Ahmet Okutan, Mehdi Mirakhorli
摘要
The notion of Attack Surface refers to the critical points on the boundary of a software system which are accessible from outside or contain valuable content for attackers. The ability to identify attack surface components of software system has a significant role in effectiveness of vulnerability analysis approaches. Most prior works focus on vulnerability techniques that use an approximation of attack surfaces and there have not been many attempts to create a comprehensive list of attack surface components. Although limited number of studies have focused on attack surface analysis, they defined attack surface components based on project specific hypotheses to evaluate security risk of specific types of software applications. In this study, we leverage a qualitative analysis approach to empirically identify an extensive list of attack surface components. To this end, we conduct a Grounded Theory (GT) analysis on 1444 previously published vulnerability reports and weaknesses with a team of three software developers and security experts. We extract vulnerability information from two publicly available repositories: 1) Common Vulnerabilities and Exposures (CVE) and 2) Common Weakness Enumeration (CWE). We ask three key questions: where the attacks come from, what they target, and how they emerge, and to help answer these questions we define three core categories for attack surface components: Entry points, Targets, and Mechanisms. We extract attack surface concepts related to each category from collected vulnerability information using the GT analysis and provide a comprehensive categorization that represents attack surface components of software systems from various perspectives. The paper introduces 254 new attack surface components that did not exist in the literature. The comparison of the proposed attack surface model with prior works indicates that only 6.7% of the identified Code level attack surface components are studied before.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper1
相关 Paper
- On Privacy Weaknesses and Vulnerabilities in Software SystemsPattaraporn Sangaroonsilp, Hoa Khanh Dam, Aditya GhoseICSE 2023 · 被引用 4 次
- Shedding Light on CVSS Scoring Inconsistencies: A User-Centric Study on Evaluating Widespread Security VulnerabilitiesJulia Wunder, Andreas Kurtz, Christian Eichenmüller, Freya Gassmann 等S&P 2024 · 被引用 25 次
- Demystifying the CVE Ecosystem: Community-Perceived Impacts and ProblemsYiliang Zhao, Hengzhi Ye, Minghui Zhou, Huaimin WangICSE 2026
- No One Drinks From the Firehose: How Organizations Filter and Prioritize Vulnerability InformationStephanie de Smale, Rik van Dijk, Xander Bouwman, Jeroen van der Ham 等S&P 2023
- Determining the Unreachable: Constraint-Guided Reachability Analysis for Dependency VulnerabilitiesWenbu Feng, Xiaohong Li, Ruitao Feng, Yao Zhang 等OOPSLA 2026 · 被引用 1 次
