Automatic Policy Synthesis and Enforcement for Protecting Untrusted Deserialization
Quan Zhang, Yiwen Xu, Zijing Yin, Chijin Zhou, Yu Jiang
摘要
—Java deserialization vulnerabilities have long been a grave security concern for Java applications. By injecting malicious objects with carefully crafted structures, attackers can reuse a series of existing methods during deserialization to achieve diverse attacks like remote code execution. To mitigate such attacks, developers are encouraged to implement policies restricting the object types that applications can deserialize. However, the design of precise policies requires expertise and significant manual effort, often leading to either the absence of policy or the implementation of inadequate ones. In this paper, we propose D ESERI G UARD , a tool designed to assist developers in securing their applications seamlessly against deserialization attacks. It can automatically formulate a policy based on the application’s semantics and then enforce it to restrict illegal deserialization attempts. First, D ESERI G UARD utilizes dataflow analysis to construct a semantic-aware property tree, which records the potential structures of deserialized objects. Based on the tree, D ESERI G UARD identifies the types of objects that can be safely deserialized and synthesizes an allowlist policy. Then, with the Java agent, D ESERI G UARD can seamlessly enforce the policy during runtime to protect various deserialization procedures. In evaluation, D ESERI G UARD successfully blocks all deserialization attacks on 12 real-world vulnerabilities. In addition, we compare D ESERI G UARD ’s automatically synthesized policies with 109 developer-designed policies. The results demonstrate that D ESERI G UARD effectively restricts 99.12% more classes. Meanwhile, we test the policy-enhanced applications with their unit tests and integration tests, which demonstrate that D ESERI G UARD ’s policies will not interfere with applications’ execution and induce a negligible time overhead of 2.17%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Janus: Detecting Rendering Bugs in Web Browsers via Visual Delta ConsistencyChijin Zhou, Quan Zhang, Bingzhou Qian, Yu JiangICSE 2025 · 被引用 2 次
- Gleipner: A Benchmark for Gadget Chain Detection in Java Deserialization VulnerabilitiesBruno Kreyssig, Alexandre BartelFSE 2025 · 被引用 2 次
- Sleeping Giants - Activating Dormant Java Deserialization Gadget Chains through Stealthy Code ChangesBruno Kreyssig, Sabine Houy, Timothée Riom, Alexandre BartelCCS 2025
- PickleBall: Secure Deserialization of Pickle-based Machine Learning ModelsAndreas D. Kellas, Neophytos Christou, Wenxin Jiang, Penghui Li 等CCS 2025
它引用的顶会 Paper3
- On the recall of static call graph construction in practiceLi Sui, Jens Dietrich, Amjed Tahir, George FourtounisICSE 2020 · 被引用 34 次
- Improving Java Deserialization Gadget Chain Mining via Overriding-Guided Object GenerationSicong Cao, Xiaobing Sun, Xiaoxue Wu, Lili Bo 等ICSE 2023 · 被引用 24 次
- ODDFuzz: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox FuzzingSicong Cao, Biao He, Xiaobing Sun, Yu Ouyang 等S&P 2023
相关 Paper
- Crystallizer: A Hybrid Path Analysis Framework to Aid in Uncovering Deserialization VulnerabilitiesPrashast Srivastava, Flavio Toffalini, Kostyantyn Vorobyov, François Gauthier 等FSE 2023 · 被引用 7 次
- QUACK: Hindering Deserialization Attacks via Static Duck TypingYaniv David, Neophytos Christou, Andreas D. Kellas, Vasileios P. Kemerlis 等NDSS 2024
- Precise and Effective Gadget Chain Mining through Deserialization Guided Call Graph ConstructionYiheng Zhang, Ming Wen, Shunjie Liu, Dongjie He 等USENIX Security 2025
- JOSer: Just-In-Time Object Serialization for Heavy Java Serialization WorkloadsChaokun Yang, Pengbo Nie, Ziyi Lin, Weipeng Wang 等ASPLOS 2026
- An In-Depth Study of More Than Ten Years of Java ExploitationPhilipp Holzinger, Stefan Triller, Alexandre Bartel, Eric BoddenCCS 2016 · 被引用 40 次
