OACAL: Finding Module-consistent Specifications to Secure Systems from Weakened User Obligations

Pengcheng Jiang, Kenji Tei

研究成果: Conference contribution

抄録

Users interacting with a system through UI are typically obliged to perform their actions in a pre-determined order, to successfully achieve certain functional goals. However, such obligations are often not followed strictly by users, which may lead to the violation to security properties, especially in security-critical systems. To improve the security with the awareness of unexpected user behaviors, a system can be redesigned to a more robust one by changing the order of actions in its specification. Meanwhile, we anticipate that the functionalities would remain consistent following the modifications. In this paper, we propose an efficient algorithm to automatically produce specification revisions tackling the attack scenarios caused by weakened user obligations. By our algorithm, all the revisions would be generated to maintain the integrity of the functionalities using a novel recomposition approach. Then, the eligible revisions that can satisfy the security requirements would be efficiently spotted by a hybrid approach combining model checking and machine learning techniques. We evaluate our algorithm by comparing its performance with a state-of-the-art approach regarding their coverage and searching speed of the desirable revisions.

本文言語English
ホスト出版物のタイトル2021 IEEE Symposium Series on Computational Intelligence, SSCI 2021 - Proceedings
出版社Institute of Electrical and Electronics Engineers Inc.
ISBN(電子版)9781728190488
DOI
出版ステータスPublished - 2021
イベント2021 IEEE Symposium Series on Computational Intelligence, SSCI 2021 - Orlando, United States
継続期間: 2021 12月 52021 12月 7

出版物シリーズ

名前2021 IEEE Symposium Series on Computational Intelligence, SSCI 2021 - Proceedings

Conference

Conference2021 IEEE Symposium Series on Computational Intelligence, SSCI 2021
国/地域United States
CityOrlando
Period21/12/521/12/7

ASJC Scopus subject areas

  • 人工知能
  • コンピュータ サイエンスの応用
  • 決定科学(その他)
  • 安全性、リスク、信頼性、品質管理
  • 制御と最適化

フィンガープリント

「OACAL: Finding Module-consistent Specifications to Secure Systems from Weakened User Obligations」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル