USENIX Security2019Top-tier venue
Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation Analysis
Yi Chen, Luyi Xing, Yue Qin, Xiaojing Liao, XiaoFeng Wang, Kai Chen, Wei Zou
Abstract
Finding logic flaws today relies on the program analysis that leverages the functionality information reported in the program's documentation. Our research, however, shows that the documentation alone may already contain information for predicting the presence of some logic flaws, even before the code is analyzed. Our first step on this direction focuses on emerging syndication services that facilitate integration of multiple payment services (e.g., Alipay, Wechat Pay, PayPal, etc.) into merchant systems. We look at whether a syndication service will cause some security requirements (e.g., checking payment against price) to become unenforceable due to losing visibility of some key parameters (e.g., payment, price) to the parties involved in the syndication, or bring in implementation errors when required security checks fail to be communicated to the developer. For this purpose, we developed a suite of Natural Language Processing techniques that enables automatic inspection of the syndication developer's guide, based upon the payment models and security requirements from the payment service. Our approach is found to be effective in identifying these potential problems from the guide, and leads to the discovery of 5 new security-critical flaws in popular Chinese merchant systems that can cause circumvention of payment once exploited.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 28d39d09-f507-45ae-a87f-c4120c839bc6Cited by top-tier papers16
- Automated Attack Synthesis by Extracting Finite State Machines from Protocol Specification DocumentsMaria Leonor Pacheco, Max von Hippel, Ben Weintraub, Dan Goldwasser et al.S&P 2022 · 58 citations
- Hermes: Unlocking Security Analysis of Cellular Network Protocols by Synthesizing Finite State Machines from Natural Language SpecificationsAbdullah Al Ishtiaq, Sarkar Snigdha Sarathi Das, Syed Md. Mukit Rashid, Ali Ranjbar et al.USENIX Security 2024 · 28 citations
- RTFM! Automatic Assumption Discovery and Verification Derivation from Library Document for API Misuse DetectionTao Lv, Ruishi Li, Yi Yang, Kai Chen et al.CCS 2020 · 27 citations
- Breaking the Specification: PDF CertificationSimon Rohlmann, Vladislav Mladenov, Christian Mainka, Jörg SchwenkS&P 2021 · 16 citations
- Detecting and Measuring Misconfigured Manifests in Android AppsYuqing Yang, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson et al.CCS 2022 · 11 citations
Builds on1
Related papers
- When Authorization Loses Its Meaning: Breaking and Fixing Third-Party Online PaymentsYongkang Xiao, Jing Chen, Min Shi, Kun He et al.USENIX Security 2026
- Messy States of Wiring: Vulnerabilities in Emerging Personal Payment SystemsJiadong Lou, Xu Yuan, Ning ZhangUSENIX Security 2021 · 4 citations
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz et al.S&P 2022 · 6 citations
- INTENTFIX: Automated Logic Vulnerability Repair via LLM-Driven Intent ModelingJinseok Heo, Dongwook Choi, Jinyoung Kim, Misoo Kim et al.ICSE 2026
- BFTDETECTOR: Automatic Detection of Business Flow Tampering for Digital Content ServiceI Luk Kim, Weihang Wang, Yonghwi Kwon, Xiangyu ZhangICSE 2023
