• DocumentCode
    3055097
  • Title

    Robustness and Security Hardening of COTS Software Libraries

  • Author

    Süßkraut, Martin ; Fetzer, Christof

  • Author_Institution
    Tech. Univ. Dresden, Dresden
  • fYear
    2007
  • fDate
    25-28 June 2007
  • Firstpage
    61
  • Lastpage
    71
  • Abstract
    COTS components, like software libraries, can be used to reduce the development effort. Unfortunately, many COTS components have been developed without a focus on robust- ness and security. We propose a novel approach to harden software libraries to improve their robustness and security. Our approach is automated, general and extensible and consists of the following stages. First, we use a static analysis to prepare and guide the following fault injection. In the dynamic analysis stage, fault injection experiments execute the library functions with both usual and extreme input values. The experiments are used to derive and verify one protection hypothesis per function (for instance, function foo fails if argument 1 is a NULL pointer). In the hardening stage, a protection wrapper is generated from these hypothesis to reject unrobust input values of library functions. We evaluate our approach by hardening a library used by Apache (a web server).
  • Keywords
    security of data; software libraries; system monitoring; Apache; COTS software libraries; dynamic analysis; fault injection; protection wrapper; security hardening; Automatic testing; Computer crashes; Performance analysis; Programming profession; Protection; Robustness; Runtime; Security; Software libraries; Software systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks, 2007. DSN '07. 37th Annual IEEE/IFIP International Conference on
  • Conference_Location
    Edinburgh
  • Print_ISBN
    0-7695-2855-4
  • Type

    conf

  • DOI
    10.1109/DSN.2007.84
  • Filename
    4272956