• DocumentCode
    660566
  • Title

    Finding architectural flaws using constraints

  • Author

    Vanciu, Radu ; Abi-Antoun, Marwan

  • Author_Institution
    Dept. of Comput. Sci., Wayne State Univ., Detroit, MI, USA
  • fYear
    2013
  • fDate
    11-15 Nov. 2013
  • Firstpage
    334
  • Lastpage
    344
  • Abstract
    During Architectural Risk Analysis (ARA), security architects use a runtime architecture to look for security vulnerabilities that are architectural flaws rather than coding defects. The current ARA process, however, is mostly informal and manual. In this paper, we propose Scoria, a semi-automated approach for finding architectural flaws. Scoria uses a sound, hierarchical object graph with abstract objects and dataflow edges, where edges can refer to nodes in the graph. The architects can augment the object graph with security properties, which can express security information unavailable in code. Scoria allows architects to write queries on the graph in terms of the hierarchy, reachability, and provenance of a dataflow object. Based on the query results, the architects enhance their knowledge of the system security and write expressive constraints. The expressiveness is richer than previous approaches that check only for the presence or absence of communication or do not track a dataflow as an object. To evaluate Scoria, we apply these constraints to several extended examples adapted from the CERT standard for Java to confirm that Scoria can detect injected architectural flaws. Next, we write constraints to enforce an Android security policy and find one architectural flaw in one Android application.
  • Keywords
    Android (operating system); Java; data flow analysis; reachability analysis; security of data; software architecture; ARA process; Android security policy; CERT standard; Java; Scoria; architectural flaws; architectural risk analysis; coding defects; dataflow edges; dataflow object; object graph; reachability; runtime architecture; security architects; security information; security property; security vulnerability; semiautomated approach; system security; Abstracts; Connectors; Encoding; Encryption; Runtime; Standards;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Automated Software Engineering (ASE), 2013 IEEE/ACM 28th International Conference on
  • Conference_Location
    Silicon Valley, CA
  • Type

    conf

  • DOI
    10.1109/ASE.2013.6693092
  • Filename
    6693092