Continuous Intrusion: Characterizing the Security of Continuous Integration Services
Yacong Gu, Lingyun Ying, Huajun Chai, Chu Qiao, Haixin Duan, Xing Gao
摘要
Continuous Integration (CI) is a widely-adopted software development practice for automated code integration. A typical CI workflow involves multiple independent stakeholders, including code hosting platforms (CHPs), CI platforms (CPs), and third party services. While CI can significantly improve development efficiency, unfortunately, it also exposes new attack surfaces. As the code executed by a CI task may come from a less-trusted user, improperly configured CI with weak isolation mechanisms might enable attackers to inject malicious code into victim software by triggering a CI task. Also, one insecure stakeholder can potentially affect the whole process. In this paper, we systematically study potential security threats in CI workflows with multiple stakeholders and major CP components considered. We design and develop an analysis tool, CInspector, to investigate potential vulnerabilities in seven popular CPs, when integrated with three mainstream CHPs. We find that all CPs have the risk of token leakage caused by improper resource sharing and isolation, and many of them utilize over-privileged tokens with improper validity periods. We further reveal four novel attack vectors that allow attackers to escalate their privileges and stealthy inject malicious code by executing a piece of code in a CI task. To understand the potential impact, we conduct a large-scale measurement on the three mainstream CHPs, scrutinizing over 1.69 million repositories. Our quantitative analysis demonstrates that some very popular repositories and large organizations are affected by these attacks. We have duly reported the identified vulnerabilities to CPs and received positive responses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- More Haste, Less Speed: Cache Related Security Threats in Continuous Integration ServicesYacong Gu, Lingyun Ying, Huajun Chai, Yingyuan Pu 等S&P 2024 · 被引用 4 次
- Action Required: A Mixed-Methods Study of Security Practices in GitHub ActionsYusuke Kubo, Fumihiro Kanei, Mitsuaki Akiyama, Takuro Wakai 等NDSS 2026 · 被引用 3 次
- The File That Contained the Keys Has Been Removed: An Empirical Analysis of Secret Leaks in Cloud Buckets and Responsible Disclosure OutcomesSoufian El Yadmani, Olga Gadyatskaya, Yury ZhauniarovichS&P 2025
- Toward Understanding the Security of Plugins in Continuous Integration ServicesXiaofan Li, Yacong Gu, Chu Qiao, Zhenkai Zhang 等CCS 2024
- Toward Understanding the Security Implications in Python Configuration FilesXinwei Yu, Zhenkai Zhang, Yuzhe Tang, Xing GaoUSENIX Security 2026
它引用的顶会 Paper16
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- A Comprehensive Formal Security Analysis of OAuth 2.0Daniel Fett, Ralf Küsters, Guido SchmitzCCS 2016 · 被引用 228 次
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 被引用 130 次
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 被引用 125 次
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 被引用 91 次
相关 Paper
- Characterizing the Security of Github CI WorkflowsIgibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee 等USENIX Security 2022
- Investigating Package Related Security Threats in Software RegistriesYacong Gu, Lingyun Ying, Yingyuan Pu, Xiao Hu 等S&P 2023
- UntrustIDE: Exploiting Weaknesses in VS Code ExtensionsElizabeth Lin, Igibek Koishybayev, Trevor Dunlap, William Enck 等NDSS 2024
- Dr. Docker: A Large-Scale Security Measurement of Docker Image EcosystemHequan Shi, Lingyun Ying, Libo Chen, Haixin Duan 等WWW 2025 · 被引用 1 次
- IDE support for cloud-based static analysesLinghui Luo, Martin Schäf, Daniel Sanchez, Eric BoddenFSE 2021 · 被引用 8 次
