KIT | KIT-Bibliothek | Impressum | Datenschutz

Detecting Information Flow Security Vulnerabilities by Analysis Coupling

Reiche, Frederik ORCID iD icon 1; Reussner, Ralf 1; Heinrich, Robert 1
1 Institut für Informationssicherheit und Verlässlichkeit (KASTEL), Karlsruher Institut für Technologie (KIT)

Abstract:

Security vulnerabilities originating from insecure information flows can violate the confidentiality of data, thereby negatively impacting individuals and service providers. This challenge gave rise to design-level analyses and source code analyses investigating information flow-related vulnerabilities. Architectural analysis, a type of design-level analysis, can detect security vulnerabilities by inspecting architectural models enriched with specifications of security-relevant information. However, the implementation may not comply with the architectural specification during software evolution. This non-compliance can result in the architectural analysis missing vulnerabilities. Consequently, vulnerabilities in the deployed system can be exploited, but the software engineers are left assuming the system to be secure. In this article, we address this problem of specification-related non-compliance by proposing a coupling approach that enables architectural analyses to use the values of security characteristics which are supplied from the implementation and retrieved by static source code analysis. Our coupling approach makes two contributions: a coupling process and the conditions necessary for the coupling (called integration conditions). ... mehr


Preprint §
DOI: 10.5445/IR/1000183239
Veröffentlicht am 29.07.2025
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Publikationstyp Zeitschriftenaufsatz
Publikationsmonat/-jahr 10.2025
Sprache Englisch
Identifikator ISSN: 0098-5589, 1939-3520, 2326-3881
KITopen-ID: 1000183239
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in IEEE Transactions on Software Engineering
Verlag Institute of Electrical and Electronics Engineers (IEEE)
Band 51
Heft 10
Seiten 2710–2743
Projektinformation FeCoMASS, 499241390 (DFG, DFG EIN, HE 8596/3-1)
Nachgewiesen in Scopus
Dimensions
OpenAlex
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page