Graduation Year

2026

Document Type

Thesis

Degree

M.S.C.S.

Degree Name

MS in Computer Science (M.S.C.S.)

Degree Granting Department

Computer Science and Engineering

Major Professor

Jarred Ligatti, Ph.D.

Committee Member

Sriram Chellappan, Ph.D.

Committee Member

Hao Zheng, Ph.D.

Keywords

Cybersecurity, Software Development, Secure Coding, Repository Security

Abstract

Hardcoded secret vulnerabilities remain a growing and persistent problem that can be difficult to mitigate once exposed. While there has been significant research and advancements in identifying and preventing hardcoded secrets, less attention has been given to understanding the risks of leaving these secrets behind in version control history, as well as analyzing the sanitization of hardcoded secrets. These challenges present a growing gap between the risk and ability to mitigate and sanitize existing secret exposures. This thesis begins to address this gap by formalizing a threat model for hardcoded secrets that persist in Git version control history after the secrets have been rotated, revoked, or otherwise updated. Our threat model serves to bring more awareness and direction to IT and cybersecurity professionals handling hardcoded secret exposure incidents. Additionally, this thesis analyzes current repository sanitization practices to derive a framework of design requirements, serving as guardrails for automated and enforceable repository sanitization systems. We apply these design requirements as SISTR (Secret Inspection and Sanitization Tool for Repositories), a graphical user interface desktop application that serves as a proof-of-concept implementation of our framework. We analyze SISTR’s functionality against a suite of test repositories injected with stale hardcoded secrets. From this evaluation, we prove the feasibility of our design requirement framework in a real application and identify a distinction in which design requirements can be enforced as opposed to voluntary, which provides insight to tool developers looking to automate repository sanitization for stale hardcoded secrets. Collectively, these contributions support the mitigation of stale hardcoded secret vulnerabilities.

Share

COinS