arrow
Return

A Credential Usage Study: Flow-Aware Leakage Detection in Open-Source Projects

delete2024-01-01
delete0
PRE
AI
R
Ruidong Han *
H
Huihui Gong
S
Siqi Ma
J
Juanru Li
C
Chang Xu
E
Elisa Bertino
‪Surya Nepal‬
Z
Zhuo Ma
马建峰 (Jianfeng Ma)
DOI:10.1109/TIFS.2023.3326985delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Authentication and cryptography are critical security functions and, thus, are very often included as part of code. These functions require using credentials, such as passwords, security tokens, and cryptographic keys. However, developers often incorrectly implement/use credentials in their code because of a lack of secure coding skills. This paper analyzes open-source projects concerning the correct use of security credentials. We developed a semantic-rich, language-independent analysis approach for analyzing many projects automatically. We implemented a detection tool, SEAGULL, to automatically check open-source projects based on string literal and code structure information. Instead of analyzing the entire project code, which might result in path explosion when constructing data and control dependencies, SEAGULL pinpoints all literal constants to identify credential candidates and then analyzes the code snippets correlated to these candidates. SEAGULL accurately identifies the leaked credentials by obtaining semantic and syntax information about the code. We applied SEAGULL to 377 open-source projects. SEAGULL successfully reported 19 real-world credential leakages out of those projects. Our analysis shows that some developers protected or erased the credentials in the current project versions, but previously used credentials can still be extracted from the project's historical versions. Although the implementations of credential leakages seem to be fixed in the current projects, attackers could successfully log into accounts if developers keep using the same credentials as before. Additionally, we found that such credential leakages still affect some projects. By exploiting leaked credentials, attackers can log into particular accounts.
Keywords:
Credential leakage
bug detection
static code analysis

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

S
shanghai jiao tong university
Scholars:
15.4W
Papers: 11.6W
Citations: 159
U
University of Sydney
Scholars:
6.5W
Papers: 6.2W
Citations: 90
Purdue University System cover
Purdue University System
Scholars:
3.9W
Papers: 3.6W
Citations: 66
P
Purdue University
Scholars:
2.6W
Papers: 2.1W
Citations: 147
X
Xidian University
Scholars:
2.4W
Papers: 1.9W
Citations: 9.7K
researcher View more organizations