Acquirer: A Hybrid Approach to Detecting Algorithmic Complexity Vulnerabilities
Yinxi Liu, Wei Meng
摘要
Algorithmic Complexity (AC) Denial-of-Service attacks have been a threat for over twenty years. Attackers craft particular input vectors to trigger the worst-case logic of some code running on the server side, which leads to high resource consumption and performance degradation. In response, several vulnerability detection tools have been developed to help developers prevent such attacks. Nevertheless, these state-of-the-art tools either focus on a specific type of vulnerability or suffer from state explosion. They are either limited to a small detection scope or unable to run efficiently. This paper aims to develop a fully automated approach to effectively and efficiently detecting AC vulnerabilities. We present the design and implementation of Acqirer, which detects AC vulnerabilities in Java programs. Acqirer first statically locates potentially vulnerable structures in the target program, then performs efficient selective path exploration to dynamically verify the existence of two different execution paths with a significant computation cost difference. The vulnerable structures it detects can also help the developers fix the corresponding vulnerabilities. We evaluated Acqirer with two widely used benchmark datasets and compared it with four state-of-the-art tools. In the evaluation, it detected 22 known AC vulnerabilities, which substantially outperformed all the existing tools together. Besides, it discovered 11 previously unknown AC vulnerabilities in popular real-world applications. Our evaluation demonstrates that Acqirer is highly effective and efficient in automatically detecting AC vulnerabilities. CCS CONCEPTS • Security and privacy → Software security engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Contextualizing Sink Knowledge for Java Vulnerability DiscoveryFabian Fleischer, Cen Zhang, Joonun Jang, Jeongin Cho 等S&P 2026 · 被引用 2 次
- Towards Automatic Detection and Exploitation of Java Web Application Vulnerabilities via Concolic Execution guided by Cross-thread Object ManipulationXinyou Huang, Lei Zhang, Yongheng Liu, Peng Deng 等USENIX Security 2025
它引用的顶会 Paper4
- SlowFuzz: Automated Domain-Independent Detection of Algorithmic Complexity VulnerabilitiesTheofilos Petsios, Jason Zhao, Angelos D. Keromytis, Suman JanaCCS 2017 · 被引用 214 次
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 被引用 125 次
- Revealer: Detecting and Exploiting Regular Expression Denial-of-Service VulnerabilitiesYinxi Liu, Mingxue Zhang, Wei MengS&P 2021 · 被引用 28 次
- HotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-FuzzingWilliam Blair, Andrea Mambretti, Sajjad Arshad, Michael Weissbacher 等NDSS 2020
相关 Paper
- ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS DetectionYeting Li, Zixuan Chen, Jialun Cao, Zhiwu Xu 等USENIX Security 2021 · 被引用 20 次
- Careless Retention and Management: Understanding and Detecting Data Retention Denial-of-Service Vulnerabilities in Java Web ContainersKeke Lian, Lei Zhang, Haoran Zhao, Yinzhi Cao 等USENIX Security 2025
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit GenerationXinyi Wang, Cen Zhang, Yeting Li, Zhiwu Xu 等S&P 2023
- An In-Depth Study of More Than Ten Years of Java ExploitationPhilipp Holzinger, Stefan Triller, Alexandre Bartel, Eric BoddenCCS 2016 · 被引用 40 次
- Exposing Resource-Exhaustion DoS Vulnerabilities with Leak-Oriented Minimum Path CoversLige Zhan, Yafei He, Jiang Ming, Guojun Peng 等USENIX Security 2026
