USENIX Security2026Top-tier venue
Exposing Resource-Exhaustion DoS Vulnerabilities with Leak-Oriented Minimum Path Covers
Lige Zhan, Yafei He, Jiang Ming, Guojun Peng, Jianming Fu
Abstract
Resource leaks---failures to properly release scarce Garbage Collection (GC)-unmanaged resources such as file descriptors, sockets, and database connections---are a pervasive root cause of resource-exhaustion denial-of-service (DoS) risks in Java programs. Prior approaches typically enumerate execution paths and inspect them to identify resources that are not properly released. However, exceptions can trigger non-local control transfers that bypass resource releases, and determining which such exceptions are leak-relevant requires context-sensitive reasoning beyond simple heuristics. Worse still, exhaustive path enumeration may trigger path explosion, significantly reducing the practicality of existing methods. Therefore, we develop LeakHunter , a novel Java resource leak detector. LeakHunter first leverages an LLM to infer leak-relevant exceptions in context and statically validates them. Next, we propose a L eak-oriented M inimum P ath C over ( LMPC ) technique. Our insight is that there is no need to enumerate all paths: since (1) leak detection is existential, a single leak-prone path suffices to demonstrate that a resource-managing object is leak-prone, and (2) we can cover the resource-relevant code regions by leveraging a minimum path cover. Therefore, we aim to select a representative path set generated from MPC while being biased toward leak-prone behaviors. Accordingly, we construct witness paths from multiple MPCs and prioritize those with more acquisitions and fewer releases as the LMPC, as they are more likely to expose leaks. Across two public benchmarks, LeakHunter achieves the best detection performance while providing an 11.4 x speedup in path analysis over the latest approach. In our real-world study, LeakHunter identifies 67 true leaks with potential DoS impact, including 15 confirmed by developers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on11
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Training language models to follow instructions with human feedbackLong Ouyang, Jeffrey Wu, Xu Jiang, Diogo Almeida et al.NeurIPS 2022 · 24,707 citations
- Rampart: Protecting Web Applications from CPU-Exhaustion Denial-of-Service AttacksWei Meng, Chenxiong Qian, Shuang Hao, Kevin Borgolte et al.USENIX Security 2018 · 32 citations
- Lightweight and modular resource leak verificationMartin Kellogg, Narges Shadab, Manu Sridharan, Michael D. ErnstFSE 2021 · 14 citations
- Mining Resource-Operation Knowledge to Support Resource Leak DetectionChong Wang, Yiling Lou, Xin Peng, Jianan Liu et al.FSE 2023 · 7 citations
Related papers
- AsyncLeakBench: A Curated Benchmark of Asynchronous Resource Leaks in Open-Source Java ProjectsJinyoung Kim, Jinseok Heo, Dongwook Choi, Eunseok LeeISSTA 2026
- From Leaks to Fixes: Automated Repairs for Resource Leak WarningsAkshay Utture, Jens PalsbergFSE 2023 · 5 citations
- Boosting Static Resource Leak Detection via LLM-based Resource-Oriented Intention InferenceChong Wang, Jianan Liu, Xin Peng, Yang Liu et al.ICSE 2025 · 5 citations
- Repairing Leaks in Resource WrappersSanjay Malakar, Michael D. Ernst, Martin Kellogg, Manu SridharanASE 2025
- JLeaks: A Featured Resource Leak Repository Collected From Hundreds of Open-Source Java ProjectsTianyang Liu, Weixing Ji, Xiaohui Dong, Wuhuang Yao et al.ICSE 2024 · 1 citation
