NAVEX: Precise and Scalable Exploit Generation for Dynamic Web Applications
Abeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. Venkatakrishnan
摘要
Modern multi-tier web applications are composed of several dynamic features, which make their vulnerability analysis challenging from a purely static analysis perspective. We describe an approach that overcomes the challenges posed by the dynamic nature of web applications. Our approach combines dynamic analysis that is guided by static analysis techniques in order to automatically identify vulnerabilities and build working exploits. Our approach is implemented and evaluated in NAVEX, a tool that can scale the process of automatic vulnerability analysis and exploit generation to large applications and to multiple classes of vulnerabilities. In our experiments, we were able to use NAVEX over a codebase of 3.2 million lines of PHP code, and construct 204 exploits in the code that was analyzed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper46
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 被引用 56 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement LearningSoyoung Lee, Seongil Wi, Sooel SonWWW 2022 · 被引用 34 次
- Unexpected Data Dependency Creation and Chaining: A New Attack to SDNFeng Xiao, Jinquan Zhang, Jianwei Huang, Guofei Gu 等S&P 2020 · 被引用 31 次
- HiddenCPG: Large-Scale Vulnerable Clone Detection Using Subgraph Isomorphism of Code Property GraphsSeongil Wi, Sijae Woo, Joyce Jiyoung Whang, Sooel SonWWW 2022 · 被引用 27 次
相关 Paper
- Automatically Learning Vulnerability Patterns for Scalable Static Analysis of Web ApplicationsPenghui Li, Songchen Yao, Josef Sarfati Korich, Changhua Luo 等CCS 2026
- Chainsaw: Chained Automated Workflow-based Exploit GenerationAbeer Alhuzali, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2016 · 被引用 52 次
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter AnalysisPenghui Li, Wei Meng, Mingxue Zhang, Chenlin Wang 等S&P 2024 · 被引用 6 次
- FIXX: FInding eXploits from eXamplesNeil P. Thimmaiah, Yashashvi J. Dave, Rigel Gjomemo, V. N. VenkatakrishnanUSENIX Security 2025
- FUGIO: Automatic Exploit Generation for PHP Object Injection VulnerabilitiesSunnyeo Park, Daejun Kim, Suman Jana, Sooel SonUSENIX Security 2022
