Finding client-side business flow tampering vulnerabilities
I Luk Kim, Yunhui Zheng, Hogun Park, Weihang Wang, Wei You, Yousra Aafer, Xiangyu Zhang
Abstract
The sheer complexity of web applications leaves open a large attack surface of business logic. Particularly, in some scenarios, developers have to expose a portion of the logic to the client-side in order to coordinate multiple parties (e.g. merchants, client users, and thirdparty payment services) involved in a business process. However, such client-side code can be tampered with on the fly, leading to business logic perturbations and financial loss. Although developers become familiar with concepts that the client should never be trusted, given the size and the complexity of the client-side code that may be even incorporated from third parties, it is extremely challenging to understand and pinpoint the vulnerability. To this end, we investigate client-side business flow tampering vulnerabilities and develop a dynamic analysis based approach to automatically identifying such vulnerabilities. We evaluate our technique on 200 popular real-world websites. With negligible overhead, we have successfully identified 27 unique vulnerabilities on 23 websites, such as New York Times, HBO, and YouTube, where an adversary can interrupt business logic to bypass paywalls, disable adblocker detection, earn reward points illicitly, etc. CCS CONCEPTS • Security and privacy → Web application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 757d0a4d-b9f8-4ca9-80f3-329d25276a76Cited by top-tier papers5
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang et al.OOPSLA 2025 · 9 citations
- App's Auto-Login Function Security Testing via Android OS-Level VirtualizationWenna Song, Jiang Ming, Lin Jiang, Han Yan et al.ICSE 2021 · 6 citations
- Adhere: Automated Detection and Repair of Intrusive AdsYutian Yan, Yunhui Zheng, Xinyue Liu, Nenad Medvidovic et al.ICSE 2023 · 2 citations
- Detecting and Explaining Anomalies Caused by Web Tamper Attacks via Building Consistency-based NormalityYifan Liao, Ming Xu, Yun Lin, Xiwen Teoh et al.ASE 2024 · 1 citation
- BFTDETECTOR: Automatic Detection of Business Flow Tampering for Digital Content ServiceI Luk Kim, Weihang Wang, Yonghwi Kwon, Xiangyu ZhangICSE 2023
Builds on1
Related papers
- Dynamic Security Analysis of JavaScript: Are We There Yet?Stefano Calzavara, Samuele Casarin, Riccardo FocardiWWW 2025 · 3 citations
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 85 citations
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer et al.NDSS 2018 · 84 citations
- U Can't Debug This: Detecting JavaScript Anti-Debugging Techniques in the WildMarius Musch, Martin JohnsUSENIX Security 2021 · 8 citations
- Automatically Learning Vulnerability Patterns for Scalable Static Analysis of Web ApplicationsPenghui Li, Songchen Yao, Josef Sarfati Korich, Changhua Luo et al.CCS 2026
