Publication View

Abstract (2008)

Abstract
This paper presents an approach to statically retrofit legacy servers with mechanisms for authorization policy enforcement. The approach is based upon the observation that security-sensitive operations performed by a server are characterized by idiomatic resource manipulations, called fingerprints. Candidate fingerprints are automatically mined by clustering resource manipulations using concept analysis. These fingerprints are then used to identify security-sensitive operations performed by the server. Case studies with three real-world servers show that the approach can be used to identify security-sensitive operations with a few hours of manual effort and modest domain knowledge. 1

Publication details
Download http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.77.9143
Source http://www.cs.wisc.edu/wisa/papers/icse07/ganapathy-mining.pdf
Contributors CiteSeerX
Repository CiteSeerX - Scientific Literature Digital Library and Search Engine (United States)
Type text
Language English
Relation 10.1.1.115.8660, 10.1.1.119.4385, 10.1.1.22.1513, 10.1.1.133.9719, 10.1.1.13.4624, 10.1.1.10.9845, 10.1.1.39.4239, 10.1.1.103.5190, 10.1.1.20.7461, 10.1.1.126.3440, 10.1.1.70.498, 10.1.1.107.3600, 10.1.1.64.5837, 10.1.1.110.7846, 10.1.1.48.8027