Finding client-side business flow tampering vulnerabilities
I Luk Kim, Yunhui Zheng, Hogun Park, Weihang Wang, Wei You, Yousra Aafer, Xiangyu Zhang
摘要
The sheer complexity of web applications leaves open a large attack surface of business logic. Particularly, in some scenarios, developers have to expose a portion of the logic to the client-side in order to coordinate multiple parties (e.g. merchants, client users, and thirdparty payment services) involved in a business process. However, such client-side code can be tampered with on the fly, leading to business logic perturbations and financial loss. Although developers become familiar with concepts that the client should never be trusted, given the size and the complexity of the client-side code that may be even incorporated from third parties, it is extremely challenging to understand and pinpoint the vulnerability. To this end, we investigate client-side business flow tampering vulnerabilities and develop a dynamic analysis based approach to automatically identifying such vulnerabilities. We evaluate our technique on 200 popular real-world websites. With negligible overhead, we have successfully identified 27 unique vulnerabilities on 23 websites, such as New York Times, HBO, and YouTube, where an adversary can interrupt business logic to bypass paywalls, disable adblocker detection, earn reward points illicitly, etc. CCS CONCEPTS • Security and privacy → Web application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang 等OOPSLA 2025 · 被引用 9 次
- App's Auto-Login Function Security Testing via Android OS-Level VirtualizationWenna Song, Jiang Ming, Lin Jiang, Han Yan 等ICSE 2021 · 被引用 6 次
- Adhere: Automated Detection and Repair of Intrusive AdsYutian Yan, Yunhui Zheng, Xinyue Liu, Nenad Medvidovic 等ICSE 2023 · 被引用 2 次
- Detecting and Explaining Anomalies Caused by Web Tamper Attacks via Building Consistency-based NormalityYifan Liao, Ming Xu, Yun Lin, Xiwen Teoh 等ASE 2024 · 被引用 1 次
- BFTDETECTOR: Automatic Detection of Business Flow Tampering for Digital Content ServiceI Luk Kim, Weihang Wang, Yonghwi Kwon, Xiangyu ZhangICSE 2023
它引用的顶会 Paper1
相关 Paper
- Dynamic Security Analysis of JavaScript: Are We There Yet?Stefano Calzavara, Samuele Casarin, Riccardo FocardiWWW 2025 · 被引用 3 次
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 被引用 85 次
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer 等NDSS 2018 · 被引用 84 次
- U Can't Debug This: Detecting JavaScript Anti-Debugging Techniques in the WildMarius Musch, Martin JohnsUSENIX Security 2021 · 被引用 8 次
- Automatically Learning Vulnerability Patterns for Scalable Static Analysis of Web ApplicationsPenghui Li, Songchen Yao, Josef Sarfati Korich, Changhua Luo 等CCS 2026
