BFTDETECTOR: Automatic Detection of Business Flow Tampering for Digital Content Service
I Luk Kim, Weihang Wang, Yonghwi Kwon, Xiangyu Zhang
Abstract
Digital content services provide users with a wide range of content, such as news, articles, or movies, while monetizing their content through various business models and promotional methods. Unfortunately, poorly designed or unpro-tected business logic can be circumvented by malicious users, which is known as business flow tampering. Such flaws can severely harm the businesses of digital content service providers. In this paper, we propose an automated approach that discov-ers business flow tampering flaws. Our technique automatically runs a web service to cover different business flows (e.g., a news website with vs. without a subscription paywall) to collect execution traces. We perform differential analysis on the execution traces to identify divergence points that determine how the business flow begins to differ, and then we test to see if the divergence points can be tampered with. We assess our approach against 352 real-world digital content service providers and discover 315 flaws from 204 websites, including TIME, Fortune, and Forbes. Our evaluation result shows that our technique successfully identifies these flaws with low false-positive and false-negative rates of 0.49% and 1.44%, respectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ce2973f7-b936-4e9b-a420-817ac7079ffdCited by top-tier papers1
Ask how each one uses itBuilds on4
- JSgraph: Enabling Reconstruction of Web Attacks via Efficient Tracking of Live In-Browser JavaScript ExecutionsBo Li, Phani Vadrevu, Kyu Hyung Lee, Roberto PerdisciNDSS 2018 · 61 citations
- Attack Patterns for Black-Box Security Testing of Multi-Party Web ApplicationsAvinash Sudhodanan, Alessandro Armando, Roberto Carbone, Luca CompagnaNDSS 2016 · 36 citations
- Finding client-side business flow tampering vulnerabilitiesI Luk Kim, Yunhui Zheng, Hogun Park, Weihang Wang et al.ICSE 2020 · 14 citations
- Detecting and understanding JavaScript global identifier conflicts on the webMingxue Zhang, Wei MengFSE 2020 · 10 citations
Related papers
- The Times They Are A-Changin': Characterizing Post-Publication Changes to Online NewsChris Tsoukaladelis, Brian Kondracki, Niranjan Balasubramanian, Nick NikiforakisS&P 2024 · 2 citations
- Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation AnalysisYi Chen, Luyi Xing, Yue Qin, Xiaojing Liao et al.USENIX Security 2019 · 33 citations
- Website-Targeted False Content Injection by Network OperatorsGabi Nakibly, Jaime Schcolnik, Yossi RubinUSENIX Security 2016 · 28 citations
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes et al.CCS 2017 · 74 citations
- Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application FirewallsQi Wang, Jianjun Chen, Zheyu Jiang, Run Guo et al.S&P 2024 · 11 citations
