论文标题

部分可观测时空混沌系统的无模型预测

Better Call Saltzer \& Schroeder: A Retrospective Security Analysis of SolarWinds \& Log4j

论文作者

Chowdhury, Partha Das, Tahaei, Mohammad, Rashid, Awais

论文摘要

Saltzer \&Schroeder的原则旨在为计算机系统设计带来安全性。我们研究了Solarwinds Orion Update和Log4J,以解开这些原理可以减轻嵌入漏洞的交叉点。未观察到的常见原则包括\ emph {fail Safe默认值},\ emph {机制经济},\ emph {完整的中介}和\ emph {最小特权}。然后,我们探索有关开发人员安全软件开发干预措施的文献,以确定可用的分析工具和框架,这些工具和框架可以改善这些原则的观察。我们专注于系统的范围访问代码,检查访问路径的访问以及具有安全库的帮助应用程序开发人员以及功能性的适当安全任务列表。

Saltzer \& Schroeder's principles aim to bring security to the design of computer systems. We investigate SolarWinds Orion update and Log4j to unpack the intersections where observance of these principles could have mitigated the embedded vulnerabilities. The common principles that were not observed include \emph{fail safe defaults}, \emph{economy of mechanism}, \emph{complete mediation} and \emph{least privilege}. Then we explore the literature on secure software development interventions for developers to identify usable analysis tools and frameworks that can contribute towards improved observance of these principles. We focus on a system wide view of access of codes, checking access paths and aiding application developers with safe libraries along with an appropriate security task list for functionalities.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源