Toward An Automated Vulnerability Comparison Of Open Source Imap Servers

LISA '05: Proceedings of the 19th conference on Large Installation System Administration Conference - Volume 19(2005)

引用 1|浏览271
暂无评分
摘要
The attack surface concept provides a means of discussing the susceptibility of software to as-yet-unknown attacks. A system's attack surface encompasses the methods the system makes available to an attacker, and the system resources which can be used to further an attack. A measurement of the size of the attack surface could be used to compare the security of multiple systems which perform the same function.The Internet Message Access Protocol (IMAP) has been in existence for over a decade. Relative to HTTP or SMTP, IMAP is a niche protocol, but IMAP servers are widely deployed nonetheless. There are three popular open source UNIX IMAP servers - UW-IMAP, Cyrus, and Courier-IMAP - and there has not been a formal security comparison between them.In this paper, I use attack surfaces to compare the relative security risks posed by these three products. I undertake this evaluation in service of two complementary goals: to provide an honest examination of the security postures and risks of the three servers, and to advance the study of attack surfaces by performing an automated attack surface measurement using a methodology based on counting entry and exit points in the code.
更多
查看译文
关键词
attack surface,attack surface concept,automated attack surface measurement,IMAP server,UNIX IMAP server,formal security comparison,relative security risk,security posture,multiple system,system resource,automated vulnerability comparison,open source IMAP server
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要