Secure Design Patterns
Chad Dougherty, Kirk Sayre, Robert C. Seacord, David Svoboda, Kazuya Togashi · 2009
The cost of fixing system vulnerabilities and the risk associated with vulnerabilities after system deployment are high for both developers and end users.While there are a number of best practices available to address the issue of software security vulnerabilities, these practices are often difficult to reuse due to the implementation-specific nature of the best practices.In addition, greater understanding of the root causes of security flaws has led to a greater appreciation of the importance of taking security into account in all phases in the software development life cycle, not just in the implementation and deployment phases.This report describes a set of secure design patterns, which are descriptions or templates describing a general solution to a security problem that can be applied in many different situations.Rather than focus on the implementation of specific security mechanisms, the secure design patterns detailed in this report are meant to eliminate the accidental insertion of vulnerabilities into code or to mitigate the consequences of vulnerabilities.The patterns were derived by generalizing existing best security design practices and by extending existing design patterns with security-specific functionality.They are categorized according to their level of abstraction: architecture, design, or implementation.// The location of the empty directory to use as the root directory // for the untrusted child process.#define EMPTY_ROOT_DIR "/home/sayre/empty_dir" /** * This defines the behavior for the spawned child, both the one with * no privileges and the one with user privileges.* * The parameters are: * * childUid -The UID to which to assign the spawned child.* * sock -The socket the child process will use for communication with * the privileged parent.*/ void handleChild(uid_t childUid, int sock) { Linux does not include a getpeereid() function.However, getpeereid() can easily be implemented as follows: /** * Get the user ID and group ID of the user connected to the other end * of the given UNIX domain socket.