ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions
Siddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl, Bradley Reaves, Antonio Bianchi, William Enck, Alexandros Kapravelos, Aravind Machiry
摘要
Millions of software projects leverage automated workflows, like GitHub Actions, for performing common build and deploy tasks. While GitHub Actions have greatly improved the software build process for developers, they pose significant risks to the software supply chain by adding more dependencies and code complexity that may introduce security bugs. This paper presents ARGUS, the first static taint analysis system for identifying code injection vulnerabilities in GitHub Actions. We used ARGUS to perform a large-scale evaluation on 2,778,483 Workflows referencing 31,725 Actions and discovered critical code injection vulnerabilities in 4,307 Workflows and 80 Actions. We also directly compared ARGUS to two existing pattern-based GitHub Actions vulnerability scanners, demonstrating that our system exhibits a marked improvement in terms of vulnerability detection, with a discovery rate more than seven times (7x) higher than the state-of-the-art approaches. These results demonstrate that command injection vulnerabilities in the GitHub Actions ecosystem are not only pervasive but also require taint analysis to be detected.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- FV8: A Forced Execution JavaScript Engine for Detecting Evasive TechniquesNikolaos Pantelaios, Alexandros KapravelosUSENIX Security 2024 · 被引用 6 次
- Action Required: A Mixed-Methods Study of Security Practices in GitHub ActionsYusuke Kubo, Fumihiro Kanei, Mitsuaki Akiyama, Takuro Wakai 等NDSS 2026 · 被引用 3 次
- Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web ApplicationsRui Yang, Haoyu Wang, Zhicheng Sun, Zhengyu Liu 等S&P 2026 · 被引用 1 次
- "It's not my responsibility to write them": An Empirical Study of Software Product Managers and Security RequirementsHouda Naji, Felix Reichmann, Tobias Bruns, M. Angela Sasse 等USENIX Security 2025
- Faster and Better: Detecting Vulnerabilities in Linux-based IoT Firmware with Optimized Reaching Definition AnalysisZicong Gao, Chao Zhang, Hangtian Liu, Wenhou Sun 等NDSS 2024
它引用的顶会 Paper4
- DR. CHECKER: A Soundy Analysis for Linux Kernel DriversAravind Machiry, Chad Spensky, Jake Corina, Nick Stephens 等USENIX Security 2017 · 被引用 126 次
- Configuration smells in continuous delivery pipelines: a linter and a six-month study on GitLabCarmine Vassallo, Sebastian Proksch, Anna Jancso, Harald C. Gall 等FSE 2020 · 被引用 43 次
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller 等ICSE 2020 · 被引用 34 次
- Characterizing the Security of Github CI WorkflowsIgibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee 等USENIX Security 2022
相关 Paper
- Argus: All your (PHP) Injection-sinks are belong to usRasoul Jahanshahi, Manuel EgeleUSENIX Security 2024 · 被引用 1 次
- COSSETER: GitHub Actions Permission Reduction Using Demand-Driven Static AnalysisGreg Tystahl, Jonah Ghebremichael, Siddharth Muralee, Sourag Cherupattamoolayil 等S&P 2026 · 被引用 3 次
- UntrustIDE: Exploiting Weaknesses in VS Code ExtensionsElizabeth Lin, Igibek Koishybayev, Trevor Dunlap, William Enck 等NDSS 2024
- Toward Understanding the Security of Plugins in Continuous Integration ServicesXiaofan Li, Yacong Gu, Chu Qiao, Zhenkai Zhang 等CCS 2024
- Comment and Control: Hijacking Agentic Workflows via Context-Grounded EvolutionNeil Fendley, Zhengyu Liu, Aonan Guan, Jiacheng Zhong 等CCS 2026
