SandDriller: A Fully-Automated Approach for Testing Language-Based JavaScript Sandboxes
Abdullah AlHamdan, Cristian-Alexandru Staicu
摘要
Language-based isolation offers a cheap way to restrict the privileges of untrusted code. Previous work proposes a plethora of such techniques for isolating JavaScript code on the client-side, enabling the creation of web mashups. While these solutions are mostly out of fashion among practitioners, there is a growing trend to use analogous techniques for JavaScript code running outside of the browser, e.g., for protecting against supply chain attacks on the serverside. Irrespective of the use case, bugs in the implementation of language-based isolation can have devastating consequences. Hence, we propose SANDDRILLER, the first dynamic analysis-based approach for detecting sandbox escape vulnerabilities. Our core insight is to design testing oracles based on two main objectives of language-based sandboxes: Prevent writes outside the sandbox and restrict access to privileged operations. Using instrumentation, we interpose oracle checks on all the references exchanged between the host and the guest code to detect foreign references that allow the guest code to escape the sandbox. If at run time, a foreign reference is detected by an oracle, SANDDRILLER proceeds to synthesize an exploit for it. We apply our approach to six sandbox systems and find eight unique zero-day sandbox breakout vulnerabilities and two crashes. We believe that SANDDRILLER can be integrated in the development process of sandboxes to detect security vulnerabilities in the pre-release phase.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScriptMasudul Hasan Masud Bhuiyan, Adithya Srinivas Parthasarathy, Nikos Vasilakis, Michael Pradel 等ICSE 2023 · 被引用 20 次
- Jack-in-the-box: An Empirical Study of JavaScript Bundling on the Web and its Security ImplicationsJeremy Rack, Cristian-Alexandru StaicuCCS 2023 · 被引用 11 次
- Bilingual Problems: Studying the Security Risks Incurred by Native Extensions in Scripting LanguagesCristian-Alexandru Staicu, Sazzadur Rahaman, Ágnes Kiss, Michael BackesUSENIX Security 2023
- Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its EcosystemAbdullah AlHamdan, Cristian-Alexandru StaicuNDSS 2025
- Test Suites Guided Vulnerability Validation for Node.js ApplicationsChanghua Luo, Penghui Li, Wei Meng, Chao ZhangCCS 2024
它引用的顶会 Paper29
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig 等NDSS 2019 · 被引用 291 次
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler 等USENIX Security 2019 · 被引用 247 次
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 被引用 178 次
相关 Paper
- Best of Both Worlds: Effective Foreign Bridge Identification in V8 Embedders for Security AnalysisGeorgios Alexopoulos, Thodoris Sotiropoulos, Zhendong Su, Dimitris MitropoulosS&P 2026 · 被引用 1 次
- JIT-Picking: Differential Fuzzing of JavaScript EnginesLukas Bernhard, Tobias Scharnowski, Moritz Schloegel, Tim Blazytko 等CCS 2022 · 被引用 42 次
- FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT CompilerJunjie Wang, Zhiyi Zhang, Shuang Liu, Xiaoning Du 等USENIX Security 2023
- FUZZILLI: Fuzzing for JavaScript JIT Compiler VulnerabilitiesSamuel Groß, Simon Koch, Lukas Bernhard, Thorsten Holz 等NDSS 2023
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer 等NDSS 2018 · 被引用 84 次
