Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web Servers
Cristian-Alexandru Staicu, Michael Pradel
摘要
Regular expression denial of service (ReDoS) is a class of algorithmic complexity attacks where matching a regular expression against an attacker-provided input takes unexpectedly long. The single-threaded execution model of JavaScript makes JavaScript-based web servers particularly susceptible to ReDoS attacks. Despite this risk and the increasing popularity of the server-side Node.js platform, there is currently little reported knowledge about the severity of the ReDoS problem in practice. This paper presents a large-scale study of ReDoS vulnerabilities in real-world web sites. Underlying our study is a novel methodology for analyzing the exploitability of deployed servers. The basic idea is to search for previously unknown vulnerabilities in popular libraries, hypothesize how these libraries may be used by servers, and to then craft targeted exploits. In the course of the study, we identify 25 previously unknown vulnerabilities in popular modules and test 2,846 of the most popular websites against them. We find that 339 web sites (11% of the ones that use Express, a popular server-side JavaScript framework) suffer from at least one ReDoS vulnerability and some even suffer from multiple ones. A single request can block a vulnerable site for several seconds, and sometimes even much longer, enabling denial of service attacks that pose a serious threat to the availability of these sites. We also show that the fact whether a website is vulnerable is independent of its popularity, indicating that the problem requires attention across a wide spectrum of web providers. Our results are a call-to-arms for developing techniques to detect and mitigate ReDoS vulnerabilities in JavaScript.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper61
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 被引用 114 次
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 被引用 91 次
- A Sense of Time for JavaScript and Node.js: First-Class Timeouts as a Cure for Event Handler PoisoningJames C. Davis, Eric R. Williamson, Dongyoon LeeUSENIX Security 2018 · 被引用 54 次
- Detecting Node.js prototype pollution vulnerabilities via object lookup analysisSong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoFSE 2021 · 被引用 49 次
它引用的顶会 Paper3
- SlowFuzz: Automated Domain-Independent Detection of Algorithmic Complexity VulnerabilitiesTheofilos Petsios, Jason Zhao, Angelos D. Keromytis, Suman JanaCCS 2017 · 被引用 214 次
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson 等NDSS 2017 · 被引用 183 次
- Tail Attacks on Web ApplicationsHuasong Shan, Qingyang Wang, Calton PuCCS 2017 · 被引用 32 次
相关 Paper
- ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS DetectionYeting Li, Zixuan Chen, Jialun Cao, Zhiwu Xu 等USENIX Security 2021 · 被引用 20 次
- Revealer: Detecting and Exploiting Regular Expression Denial-of-Service VulnerabilitiesYinxi Liu, Mingxue Zhang, Wei MengS&P 2021 · 被引用 28 次
- Runtime Recovery of Web Applications under Zero-Day ReDoS AttacksZhihao Bai, Ke Wang, Hang Zhu, Yinzhi Cao 等S&P 2021 · 被引用 19 次
- Towards an Effective Method of ReDoS Detection for Non-backtracking EnginesWeihao Su, Hong Huang, Rongchen Li, Haiming Chen 等USENIX Security 2024 · 被引用 4 次
- Careless Retention and Management: Understanding and Detecting Data Retention Denial-of-Service Vulnerabilities in Java Web ContainersKeke Lian, Lei Zhang, Haoran Zhao, Yinzhi Cao 等USENIX Security 2025
