An In-Depth Study of More Than Ten Years of Java Exploitation
Philipp Holzinger, Stefan Triller, Alexandre Bartel, Eric Bodden
摘要
When created, the Java platform was among the first runtimes designed with security in mind. Yet, numerous Java versions were shown to contain far-reaching vulnerabilities, permitting denial-of-service attacks or even worse allowing intruders to bypass the runtime's sandbox mechanisms, opening the host system up to many kinds of further attacks. This paper presents a systematic in-depth study of 87 publicly available Java exploits found in the wild. By collecting, minimizing and categorizing those exploits, we identify their commonalities and root causes, with the goal of determining the weak spots in the Java security architecture and possible countermeasures. Our findings reveal that the exploits heavily rely on a set of nine weaknesses, including unauthorized use of restricted classes and confused deputies in combination with caller-sensitive methods. We further show that all attack vectors implemented by the exploits belong to one of three categories: single-step attacks, restricted-class attacks, and information hiding attacks. The analysis allows us to propose ideas for improving the security architecture to spawn further research in this area.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Economic Factors of Vulnerability Trade and ExploitationLuca AllodiCCS 2017 · 被引用 82 次
- Hardening Java's Access Control by Abolishing Implicit Privilege ElevationPhilipp Holzinger, Ben Hermann, Johannes Lerch, Eric Bodden 等S&P 2017 · 被引用 12 次
- Unveiling the Invisible: Detection and Evaluation of Prototype Pollution Gadgets with Dynamic Taint AnalysisMikhail Shcherbakov, Paul Moosbrugger, Musard BalliuWWW 2024 · 被引用 8 次
- GHunter: Universal Prototype Pollution Gadgets in JavaScript RuntimesEric Cornelissen, Mikhail Shcherbakov, Musard BalliuUSENIX Security 2024 · 被引用 5 次
- FAIL: Analyzing Software Failures from the News Using LLMsDharun Anandayuvaraj, Matthew Campbell, Arav Tewari, James C. DavisASE 2024 · 被引用 3 次
相关 Paper
- Careless Retention and Management: Understanding and Detecting Data Retention Denial-of-Service Vulnerabilities in Java Web ContainersKeke Lian, Lei Zhang, Haoran Zhao, Yinzhi Cao 等USENIX Security 2025
- Towards Automatic Detection and Exploitation of Java Web Application Vulnerabilities via Concolic Execution guided by Cross-thread Object ManipulationXinyou Huang, Lei Zhang, Yongheng Liu, Peng Deng 等USENIX Security 2025
- SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive PerspectiveYinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu 等NDSS 2026 · 被引用 3 次
- Improving Java Deserialization Gadget Chain Mining via Overriding-Guided Object GenerationSicong Cao, Xiaobing Sun, Xiaoxue Wu, Lili Bo 等ICSE 2023 · 被引用 24 次
- Understanding and Finding Java Decompiler BugsYifei Lu, Weidong Hou, Minxue Pan, Xuandong Li 等OOPSLA 2024 · 被引用 5 次
