A Software Composition Flaw in Google Desktop Search
نویسندگان
چکیده
Modern software systems are composed of different modules and objects that interact with each other. Each of these components may satisfy a local security policy. It may also satisfy a global security policy with respect to its intended operating environment. However, when many components are put together, because of unexpected interactions among them, a local security policy and/or the global security policy may be violated. A composition flaw is when the execution of a composition of separately secure components leads to a system state in which a local or the global security policy is invalidated. We are particularly interested in composition flaws at the design, not code level and therefore are currently exploring the nature of these flaws so we can detect them automatically before the composition is performed. Our long-term goal is to identify new kinds of composition flaws before attackers discover and exploit them. As a first step towards this goal we show an analysis of a recent composition flaw discovered in the Google Desktop Search application, a flaw that compromises users’ privacy. We show the principles of this type of flaws and describe our approach to detecting them.
منابع مشابه
"openness of search engine": A critical flaw in search systems; a case study on google, yahoo and bing
There is no doubt that Search Engines are playing a great role in Internet usage. But all the top search engines Google, Yahoo and Bing are having a critical flaw called “Openness of a Search Engine”. An Internet user should be allowed to get the search results only when requested through Search engine’s web page but the user must not be allowed to get the search results when requested through ...
متن کاملExtracting Evidence Using Google Desktop Search
Desktop search applications have improved dramatically over the last three years, evolving from time-consuming search applications to instantaneous search tools that rely extensively on pre-cached data. This paper investigates the extraction of pre-cached data for forensic purposes, drawing on earlier work to automate the process. The result is a proof-of-concept application called Google Deskt...
متن کاملAttacks on Local Searching Tools
The Google Desktop Search is an indexing tool, currently in beta testing, designed to allow users fast, intuitive, searching for local files. The principle interface is provided through a local web server which supports an interface similar to Google.com’s normal web page. Indexing of local files occurs when the system is idle, and understands a number of common file types. A optional feature i...
متن کاملDesktop Search - How Contextual Information Influences Search Results & Rankings
1. MOTIVATION Sophisticated web search technology usually allows us to find appropriate documents in a few seconds. Finding these documents on our desktop is surprisingly more difficult, at least if we have been storing documents for a few years or more. This is improving somewhat with the recent crop of desktop search engines, but even with these tools, searching through our (relatively small ...
متن کاملI know I stored it somewhere - Contextual Information and Ranking on our Desktop
1 Motivation Future digital libraries will be distributed, and recent research has already explored some promising approaches focusing on distributed and peer-to-peer search and retrieval architectures, connecting distributed repositories efficiently and transparently. Another aspect, which has been less explored so far, is the role of the implicit personal repositories we all have on our deskt...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005