Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint Analysis
Yuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang, Jingzhu He
摘要
Server-side request forgery (SSRF) vulnerabilities are inevitable in PHP web applications. Existing static tools in detecting vulnerabilities in PHP web applications neither contain SSRF-related features to enhance detection accuracy nor consider PHP's dynamic type features. In this paper, we present Artemis 1 , a static taint analysis tool for detecting SSRF vulnerabilities in PHP web applications. First, Artemis extracts both PHP built-in and third-party functions as candidate source and sink functions. Second, Artemis constructs both explicit and implicit call graphs to infer functions' relationships. Third, Artemis performs taint analysis based on a set of rules that prevent over-tainting and pauses when SSRF exploitation is impossible. Fourth, Artemis analyzes the compatibility of path conditions to prune false positives. We have implemented a prototype of Artemis and evaluated it on 250 PHP web applications. Artemis reports 207 true vulnerable paths (106 true SSRFs) with 15 false positives. Of the 106 detected SSRFs, 35 are newly found and reported to developers, with 24 confirmed and assigned CVE IDs.
CCS Concepts: • Software and its engineering → Automated static analysis; • Security and privacy → Web application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum InfrastructureJie Ma, Ningyu He, Jinwen Xi, Mingzhe Xing 等OOPSLA 2026
- State-Aware Fuzzing of JavaScript Engines with LLM-Guided InstrumentationWai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Ping Fan Ke 等SOSP 2026
它引用的顶会 Paper29
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 被引用 85 次
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes 等CCS 2017 · 被引用 74 次
- JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative TraversalsSoheil Khodayari, Giancarlo PellegrinoUSENIX Security 2021 · 被引用 51 次
- Detecting Node.js prototype pollution vulnerabilities via object lookup analysisSong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoFSE 2021 · 被引用 49 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
相关 Paper
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang 等S&P 2024 · 被引用 15 次
- TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP ApplicationsChanghua Luo, Penghui Li, Wei MengCCS 2022 · 被引用 27 次
- Argus: All your (PHP) Injection-sinks are belong to usRasoul Jahanshahi, Manuel EgeleUSENIX Security 2024 · 被引用 1 次
- ZIPPER: Static Taint Analysis for PHP Applications with Precision and EfficiencyXinyi Wang, Yeting Li, Jie Lu, Shizhe Cui 等USENIX Security 2025
- CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web ApplicationsYichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo 等ICSE 2026
