IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social Networks
Paul Marinescu, Chad Parry, Marjori Pomarole, Yuan Tian, Patrick Tague, Ioannis Papagiannis
Abstract
Authorization bugs, when present in online social networks, are usually caused by missing or incorrect authorization checks and can allow attackers to bypass the online social network's protections. Unfortunately, there is no practical way to fully guarantee that an authorization bug will never be introduced-even with good engineering practices-as a web application and its data model become more complex. Unlike other web application vulnerabilities such as XSS and CSRF, there is no practical general solution to prevent missing or incorrect authorization checks.
In this paper we propose INVARIANT DETECTOR (IVD), a defense-in-depth system that automatically learns authorization rules from normal data manipulation patterns and distills them into likely invariants. These invariants, usually learned during the testing or pre-release stages of new features, are then used to block any requests that may attempt to exploit bugs in the social network's authorization logic. IVD acts as an additional layer of defense, working behind the scenes, complementary to privacy frameworks and testing.
We have designed and implemented IVD to handle the unique challenges posed by modern online social networks. IVD is currently running at Facebook, where it infers and evaluates daily more than 200,000 invariants from a sample of roughly 500 million client requests, and checks the resulting invariants every second against millions of writes made to a graph database containing trillions of entities. Thus far IVD has detected several high impact authorization bugs and has successfully blocked attempts to exploit them before code fixes were deployed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a34a9239-efd2-4319-bc1f-1e6345a5a351Cited by top-tier papers3
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg et al.USENIX Security 2017 · 46 citations
- GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesIsaac Polinsky, Pubali Datta, Adam Bates, William EnckWWW 2024 · 15 citations
- DELF: Safeguarding deletion correctness in Online Social NetworksKatriel Cohn-Gordon, Georgios Damaskinos, Divino Neto, Joshi Cordova et al.USENIX Security 2020
Related papers
- Deep Entity Classification: Abusive Account Detection for Online Social NetworksTeng Xu, Gerard Goossen, Huseyin Kerem Cevahir, Sara Khodeir et al.USENIX Security 2021 · 41 citations
- Detecting and Explaining Anomalies Caused by Web Tamper Attacks via Building Consistency-based NormalityYifan Liao, Ming Xu, Yun Lin, Xiwen Teoh et al.ASE 2024 · 1 citation
- Invetter: Locating Insecure Input Validations in Android ServicesLei Zhang, Zhemin Yang, Yuyu He, Zhenyu Zhang et al.CCS 2018 · 30 citations
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 59 citations
- Learning semantic program embeddings with graph interval neural networkYu Wang, Ke Wang, Fengjuan Gao, Linzhang WangOOPSLA 2020 · 61 citations
