BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface
Mingi Jung, Donggyu Kim, Mijung Kim, Seongil Wi
摘要
Modern web ecosystems rely on security policy headers, such as Content Security Policy (CSP) and the SameSite cookie attribute, for client-side defenses. Because browsers enforce these headers, browser bugs in policy enforcement directly undermine these defenses. While recent studies have attempted to find such bugs, they largely overlook bugs triggered by user interactions on the browser user interface (BUI).
In this paper, we propose BUIZZ, the first testing framework that identifies policy enforcement bugs triggered by BUI-level user interactions. BUIZZ first collects a comprehensive set of interactions by referencing browser manuals, right-click context menus, and known browser bugs. It then executes each interaction and their combinations on the test pages via OS-level simulation. Instead of cross-browser differential testing, BUIZZ leverages a pre/post-interaction oracle that checks for enforcement inconsistencies before and after applying interactions, enabling bug detection within a single browser. We demonstrate the efficacy of BUIZZ by finding 35 security bugs and three functional bugs across six browsers, including Chrome and Firefox. Our reports have led to fixes for 14 security bugs, resulting in seven CVEs and $14,700 in bug bounties.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper39
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 被引用 382 次
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 被引用 178 次
- IMF: Inferred Model-based FuzzerHyungSeok Han, Sang Kil ChaCCS 2017 · 被引用 139 次
- Fuzzing JavaScript Engines with Aspect-preserving MutationSoyeon Park, Wen Xu, Insu Yun, Daehee Jang 等S&P 2020 · 被引用 126 次
相关 Paper
- DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential TestingSeongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock 等NDSS 2023
- Head(er)s Up! Detecting Security Header Inconsistencies in BrowsersJannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben StockCCS 2025
- Web Platform Threats: Automated Detection of Web Security Issues With WPTPedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara 等USENIX Security 2024 · 被引用 6 次
- A Bug's Life: Analyzing the Lifecycle and Mitigation Process of Content Security Policy BugsGertjan Franken, Tom van Goethem, Lieven Desmet, Wouter JoosenUSENIX Security 2023
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes 等USENIX Security 2020
