Skip to main content
QUICK REVIEW

[논문 리뷰] Stronger Enforcement of Security Using AOP and Spring AOP

Kotrappa Sirbi, Prakash Kulkarni|arXiv (Cornell University)|2010. 06. 23.
Advanced Software Engineering Methodologies참고 문헌 1인용 수 5
한 줄 요약

이 논문은 객체지향 응용 프로그램에서 접근 제어 및 정보 분류와 같은 횡단 관심사의 모odular화를 통해 보안 강화를 위해 Aspect-Oriented Programming (AOP), 특히 AspectJ와 Spring AOP를 제안한다. 컴파일 타임(AspectJ)과 런타임(스프링 AOP)에서 보안 관련 요소를 응용 프로그램에 통합함으로써, 코드의 얽힘과 산산이 흩어짐을 줄여 보다 일관되고 재사용 가능하며 강력한 보안 정책을 구현할 수 있으며, 스프링 AOP는 기존의 OOP나 기본적인 AOP 접근 방식보다 런타임에서 더 강력한 보안 강제를 보여준다.

ABSTRACT

An application security has two primary goals: first, it is intended to prevent unauthorised personnel from accessing information at higher classification than their authorisation. Second, it is intended to prevent personnel from declassifying information. Using an object oriented approach to implementing application security results not only with the problem of code scattering and code tangling, but also results in weaker enforcement of security. This weaker enforcement of security could be due to the inherent design of the system or due to a programming error. Aspect Oriented Programming (AOP) complements Object-Oriented Programming (OOP) by providing another way of thinking about program structure. The key unit of modularity in OOP is the class, whereas in AOP the unit of modularity is the aspect. The goal of the paper is to present that Aspect Oriented Programming AspectJ integrated with Spring AOP provides very powerful mechanisms for stronger enforcement of security.Aspect-oriented programming (AOP) allows weaving a security aspect into an application providing additional security functionality or introducing completely new security mechanisms.Implementation of security with AOP is a flexible method to develop separated, extensible and reusable pieces of code called aspects.In this comparative study paper, we argue that Spring AOP provides stronger enforcement of security than AspectJ.We have shown both Spring AOP and AspectJ strive to provide a comprehensive AOP solutions and complements each other.

연구 동기 및 목표

  • 기존의 OOP가 코드의 산산이 흩어짐과 얽힘으로 인해 보안 정책을 강제하는 데 한계를 보이는 점을 해결하기 위해.
  • AOP가 접근 제어 및 데이터 분류와 같은 보안 관심사를 어떻게 모듈화할 수 있는지 조사하기 위해.
  • 기존의 OOP보다 보다 강력하게 보안 정책을 강제하는 데 AspectJ와 스프링 AOP의 효과성을 비교하기 위해.
  • AOP 기반의 보안 강제가 더 유지보수성과 확장성, 일관성이 높은 보안 메커니즘을 제공함을 보여주기 위해.

제안 방법

  • 보안 관련 요소를 응용 프로그램 코드베이스에 컴파일 타임에 통합하기 위해 AspectJ 통합.
  • 프록시를 통한 런타임에서의 보안 로직 통합을 통해 동적 보안 검사를 가능하게 하기 위해 스프링 AOP 사용.
  • 재사용 가능한 모듈로써 권한 부여 및 분류 해제 제어 로직을 캡슐화한 보안 관련 요소 정의.
  • 보안 검사를 필요로 하는 특정 메서드나 클래스를 대상으로 포인트컷 적용.
  • 보안 로직을 비즈니스 로직에서 분리하여 결합도를 낮추기 위해 AOP의 관심사 분리 원칙 활용.
  • 실제 응용 프로그램 환경에서 스프링 AOP와 AspectJ 간의 보안 강제 강도를 비교하는 연구를 통해 접근 방식 평가.

실험 결과

연구 질문

  • RQ1기존의 OOP 접근 방식에 비해 AOP는 보안 강제의 모듈성과 유지보수성에 어떻게 기여하는가?
  • RQ2AspectJ와 스프링 AOP는 강제적 접근 제어를 어떻게 강력하게 구현하고 정보 분류 해제를 방지할 수 있는가?
  • RQ3컴파일 타임(AspectJ)과 런타임(스프링 AOP)의 통합 메커니즘 간의 보안 강제 강도에 어떤 차이가 있는가?
  • RQ4기존의 비즈니스 로직을 수정하지 않고도 AOP를 사용해 보안 정책을 더 재사용 가능하고 플러그인 방식으로 만들 수 있는가?
  • RQ5AOP는 객체지향 시스템에서 보안 강제를 약화시키는 프로그래밍 오류의 위험을 어떻게 완화하는가?

주요 결과

  • 보안 로직을 전용 어셈블리로 캡슐화함으로써 AOP는 코드의 산산이 흩어짐과 얽힘을 크게 줄여 코드의 명확성과 유지보수성을 향상시킨다.
  • 기존의 OOP나 기본적인 AOP 접근 방식에 비해 스프링 AOP는 보다 강력한 런타임 보안 정책 강제를 제공한다.
  • AOP의 관심사 분리 덕분에 접근 제어 및 분류 정책의 일관되고 재사용 가능한 구현이 가능해진다.
  • 기존의 비즈니스 로직을 수정하지 않고도 보안 관련 요소를 응용 프로그램에 통합할 수 있어 확장성과 모듈성이 향상된다.
  • AspectJ와 스프링 AOP의 통합은 서로 다른 배포 환경에서 상호 보완적인 보완을 제공하는 종합적인 솔루션을 제공한다.
  • 비교 연구를 통해 AOP 기반의 보안 강제는 단일 구조의 OOP 구현에 비해 더 견고하고 오류 발생 가능성이 낮다는 것이 확인되었다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.