@inproceedings{04c5337965184d3fb696bada125cc724,
title = "Securely handling application-to-application connection credentials",
abstract = "The utilization of application-to-application credentials within interpretive language scripts and application code has long been a security risk. The quandaries being how to protect and secure the credentials embedded in source code and avoid exploitation from rogue programmers, sys admins and other users with authorized high levels of privilege. To date the pervasive method for addressing this has been to live with the risk and concentrate on mitigating the impact of expected and eventual exploitation. Recently published research efforts support the pervasive acceptance of this risk by such stayed auditing bodies such as the Institute of Internal Auditing (IIA) and the Information Systems Audit and Control Association (ISCAA). Numerous research efforts have taken place were built on the premise that nothing can be done to avoid the risk so it is best to concentrate the research on reducing the impact of exploitation. The research presented in this paper develops a method by which interpretive language scripts can request credentials from a commercial password vault and have those credentials returned to the script in such a manner as to reduce the risk of exploit significantly over generally accepted methods for credential handling. ",
keywords = "aspect oriented, connection credentials, pass word vault, security",
author = "Gary Lieberman and Mitropoulos, \{Frank J.\}",
year = "2013",
doi = "10.1109/SECON.2013.6567464",
language = "English",
isbn = "9781479900527",
series = "2013 Proceedings of IEEE Southeastcon",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
booktitle = "Conference Proceedings - IEEE SOUTHEASTCON",
note = "IEEE SoutheastCon 2013: Moving America into the Future ; Conference date: 04-04-2013 Through 07-04-2013",
}