Understanding and detecting server-side request races in web applications
Zhengyi Qiu, Shudi Shao, Qi Zhao, Guoliang Jin
Abstract
Modern web sites often run web applications on the server to handle HTTP requests from users and generate dynamic responses. Due to their concurrent nature, web applications are vulnerable to serverside request races. The problem becomes more severe with the ever-increasing popularity of web applications.
We first conduct a comprehensive characteristic study of 157 realworld server-side request races collected from different, popular types of web applications. The findings of this study can provide guidance for future development support in combating server-side request races.
Guided by our study results, we develop a dynamic framework, ReqRacer, for detecting and exposing server-side request races in web applications. We propose novel approaches to model happensbefore relationships between HTTP requests, which are essential to web applications. Our evaluation shows that ReqRacer can effectively and efficiently detect known and unknown request races.
• Software and its engineering → Software defect analysis; Software reliability; Software testing and debugging; Concurrency control; Organizing principles for web applications; Consistency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5c1ae1aa-4e68-4761-80b4-af0576a696c8Related papers
- Racedb: Detecting Request Race Vulnerabilities in Database-Backed Web ApplicationsAn Chen, Yonghwi Kwon, Kyu Hyung LeeS&P 2025
- Race Detection for Event-Driven Node.js ApplicationsXiaoning Chang, Wensheng Dou, Jun Wei, Tao Huang et al.ASE 2021 · 6 citations
- A study of real-world data races in GolangMilind Chabbi, Murali Krishna RamanathanPLDI 2022 · 34 citations
- Optimistic Prediction of Synchronization-Reversal Data RacesZheng Shi, Umang Mathur, Andreas PavlogiannisICSE 2024 · 8 citations
- Towards Automatic Detection and Exploitation of Java Web Application Vulnerabilities via Concolic Execution guided by Cross-thread Object ManipulationXinyou Huang, Lei Zhang, Yongheng Liu, Peng Deng et al.USENIX Security 2025
