Death by a Thousand Drips: Uncovering Critical Resource Leaks in the Windows Ecosystem
Feng Dong, Jianting Gao, Yunpeng Tian, Weifeng Yuan, Mu Zhang, Zesen Ye, Jietao Yang, Zhiniang Peng
摘要
Windows remote services are a critical attack surface due to their privileged execution and widespread deployment. Under the shared service-host model (svchost.exe), a single resource-exhaustion bug can trigger fate-sharing failures across co-resident services. Yet most vulnerability discovery remains crash-centric and is thus blind to silent, long-horizon resource leaks (e.g., memory/handle exhaustion) that do not cause immediate exceptions, while the closed-source Windows ecosystem limits the applicability of source-level sanitizers. We present REDOSPECTOR, a fuzzing framework for discovering resource-oriented Denial-of-Service (DoS) vulnerabilities in opaque Windows binaries. REDOSPECTOR combines (1) lightweight in-process hook-based telemetry by intercepting native ntdll heap routines, (2) an amplification-based oracle that identifies persistent leaks via repeated execution and growth-trend analysis, and (3) a hybrid seed-generation pipeline that leverages static binary analysis and Large Language Models (LLMs) to reach deep protocol states. Evaluated on the latest builds of Windows 11 (24H2) and Windows Server Preview, REDOSPECTOR uncovers 19 vulnerabilities in core services (including MSMQ, Remote Desktop Gateway, and CDP), leading to 12 assigned CVEs. Microsoft confirmed seven pre-authentication DoS issues in CDP and performed architectural adjustments, demonstrating that REDOSPECTOR can expose resource-mismanagement flaws that evade conventional fuzzing.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- SlowFuzz: Automated Domain-Independent Detection of Algorithmic Complexity VulnerabilitiesTheofilos Petsios, Jason Zhao, Angelos D. Keromytis, Suman JanaCCS 2017 · 被引用 214 次
- MemLock: memory usage guided fuzzingCheng Wen, Haijun Wang, Yuekang Li, Shengchao Qin 等ICSE 2020 · 被引用 116 次
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang 等USENIX Security 2016 · 被引用 107 次
- Automatically Detecting Error Handling Bugs Using Error SpecificationsSuman Jana, Yuan Jochen Kang, Samuel Roth, Baishakhi RayUSENIX Security 2016 · 被引用 79 次
- Digtool: A Virtualization-Based Framework for Detecting Kernel VulnerabilitiesJianfeng Pan, Guanglu Yan, Xiaocao FanUSENIX Security 2017 · 被引用 44 次
相关 Paper
- Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC SeaHaoyi Liu, Feng Dong, Yunpeng Tian, Mu Zhang 等CCS 2025
- Autonomy Comes with Costs: Detecting Denial-of-Service Vulnerabilities Caused by Resource Abusing in LLM-based AgentsJiaqi Luo, Jiarun Dai, Fengyu Liu, Songyang Peng 等USENIX Security 2026
- Regulator: Dynamic Analysis to Detect ReDoSRobert McLaughlin, Fabio Pagani, Noah Spahn, Christopher Kruegel 等USENIX Security 2022
- ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS DetectionYeting Li, Zixuan Chen, Jialun Cao, Zhiwu Xu 等USENIX Security 2021 · 被引用 20 次
- LifeFuzz: Lifecycle-Guided Fuzzing for Windows Driver Cross-Handler VulnerabilitiesChendong Yu, Yuekang Li, Yang Xiao, Jie Lu 等EuroSys 2026
