Seneca: Taint-Based Call Graph Construction for Java Object Deserialization
Joanna C. S. Santos, Mehdi Mirakhorli, Ali Shokri
Abstract
Object serialization and deserialization are widely used for storing and preserving objects in les, memory, or database as well as for transporting them across machines, enabling remote interaction among processes and many more. This mechanism relies on reection, a dynamic language that introduces serious challenges for static analyses. Current state-of-the-art call graph construction algorithms do not fully support object serialization/deserialization, i.e., they are unable to uncover the callback methods that are invoked when objects are serialized and deserialized. Since call graphs are a core data structure for multiple types of analysis (e.g., vulnerability detection), an appropriate analysis cannot be performed since the call graph does not capture hidden (vulnerable) paths that occur via callback methods. In this paper, we present S, an approach for handling serialization with improved soundness in the context of call graph construction. Our approach relies on taint analysis and API modeling to construct sound call graphs. We evaluated our approach with respect to soundness, precision, performance, and usefulness in detecting untrusted object deserialization vulnerabilities. Our results show that S can create sound call graphs with respect to serialization features. The resulting call graphs do not incur signicant runtime overhead and were shown to be useful for performing identication of vulnerable paths caused by untrusted object deserialization.
CCS Concepts: • Software and its engineering ! Automated static analysis; Software verication and validation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang et al.OOPSLA 2025 · 9 citations
- Gleipner: A Benchmark for Gadget Chain Detection in Java Deserialization VulnerabilitiesBruno Kreyssig, Alexandre BartelFSE 2025 · 2 citations
- Sleeping Giants - Activating Dormant Java Deserialization Gadget Chains through Stealthy Code ChangesBruno Kreyssig, Sabine Houy, Timothée Riom, Alexandre BartelCCS 2025
Builds on4
- Static analysis of Java enterprise applications: frameworks and caches, the elephants in the roomAnastasios Antoniadis, Nikos Filippakis, Paddy Krishnan, Raghavendra Ramesh et al.PLDI 2020 · 41 citations
- On the recall of static call graph construction in practiceLi Sui, Jens Dietrich, Amjed Tahir, George FourtounisICSE 2020 · 34 citations
- ODDFuzz: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox FuzzingSicong Cao, Biao He, Xiaobing Sun, Yu Ouyang et al.S&P 2023
- SerialDetector: Principled and Practical Exploration of Object Injection Vulnerabilities for the WebMikhail Shcherbakov, Musard BalliuNDSS 2021
Related papers
- Precise and Effective Gadget Chain Mining through Deserialization Guided Call Graph ConstructionYiheng Zhang, Ming Wen, Shunjie Liu, Dongjie He et al.USENIX Security 2025
- Call Graph Soundness in Android Static AnalysisJordan Samhi, René Just, Tegawendé F. Bissyandé, Michael D. Ernst et al.ISSTA 2024 · 8 citations
- QUACK: Hindering Deserialization Attacks via Static Duck TypingYaniv David, Neophytos Christou, Andreas D. Kellas, Vasileios P. Kemerlis et al.NDSS 2024
- GadgetHunter: Region-Based Neuro-symbolic Detection of Java Deserialization VulnerabilitiesKaixuan Li, Jian Zhang, Chong Wang, Sen Chen et al.FSE 2026
- Static Analysis of Remote Procedure Call in Java ProgramsBaoquan Cui, Rong Qu, Zhen Tang, Jian ZhangICSE 2025
