MOCGuard: Automatically Detecting Missing-Owner-Check Vulnerabilities in Java Web Applications
Fengyu Liu, Youkun Shi, Yuan Zhang, Guangliang Yang, Enhao Li, Min Yang
摘要
Java web applications have been extensively utilized for hosting and powering high-value commercial websites. However, their intricate complexities leave them susceptible to a critical security flaw, named Missing-Owner-Check (MOC), that may expose websites to unauthorized access and data breaches. However, the research on identifying and analyzing MOC vulnerabilities has been limited over the years. In this work, we propose a novel end-to-end vulnerability analysis approach, called MOCGuard, that can effectively vet Java web applications against MOC issues. Different from related techniques, MOCGuard pinpoints MOC vulnerabilities from a new perspective of database-centric analysis. MOCGuard first applies database structure analysis to infer user table and user-owned data. Then, MOCGuard conducts insecure access checks across both the Java and SQL layers. To thoroughly evaluate the effectiveness of MOCGuard, we collaborated with a world-leading tech company. Through our evaluation of 30 high-profile open-source Java web applications and 7 industrial Java web applications, we demonstrate that MOCGuard is automatic and effective. Consequently, it successfully uncovered 161 (confirmed) 0-day MOC vulnerabilities, leading to the assignment of 73 CVE identifiers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Detecting Privilege Escalation in Polyglot Microservices via Agentic Program AnalysisPenghui Li, Hong Yau Chong, Yinzhi Cao, Junfeng YangS&P 2026 · 被引用 3 次
- Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web ApplicationsQiyi Zhang, Fengyu Liu, Zihan Lin, Yuan ZhangCCS 2025
- BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Enhao Li, Wei Meng 等CCS 2025
- XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent FuzzingYoukun Shi, Yuan Zhang, Tianhao Bai, Feng Xue 等USENIX Security 2025
- 403 Forbidden? Ethically Evaluating Broken Access Control in the WildSaiid El Hajj Chehade, Florian Hantke, Ben StockS&P 2025
它引用的顶会 Paper13
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 被引用 85 次
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung 等USENIX Security 2019 · 被引用 77 次
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 被引用 65 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- Static analysis of Java enterprise applications: frameworks and caches, the elephants in the roomAnastasios Antoniadis, Nikos Filippakis, Paddy Krishnan, Raghavendra Ramesh 等PLDI 2020 · 被引用 41 次
相关 Paper
- Careless Retention and Management: Understanding and Detecting Data Retention Denial-of-Service Vulnerabilities in Java Web ContainersKeke Lian, Lei Zhang, Haoran Zhao, Yinzhi Cao 等USENIX Security 2025
- Precise (Un)Affected Version Analysis for Web VulnerabilitiesYoukun Shi, Yuan Zhang, Tianhan Luo, Xiangyu Mao 等ASE 2022 · 被引用 7 次
- Effective Directed Fuzzing with Hierarchical Scheduling for Web Vulnerability DetectionZihan Lin, Yuan Zhang, Jiarun Dai, Xinyou Huang 等USENIX Security 2025
- Towards Automatic Detection and Exploitation of Java Web Application Vulnerabilities via Concolic Execution guided by Cross-thread Object ManipulationXinyou Huang, Lei Zhang, Yongheng Liu, Peng Deng 等USENIX Security 2025
- Detecting Taint-Style Vulnerabilities in Microservice-Structured Web ApplicationsFengyu Liu, Yuan Zhang, Tian Chen, Youkun Shi 等S&P 2025
