Revealing injection vulnerabilities by leveraging existing tests
Katherine Hough, Gebrehiwet B. Welearegai, Christian Hammer, Jonathan Bell
摘要
Code injection attacks, like the one used in the high-pro le 2017 Equifax breach, have become increasingly common, now ranking #1 on OWASP's list of critical web application vulnerabilities. Static analyses for detecting these vulnerabilities can overwhelm developers with false positive reports. Meanwhile, most dynamic analyses rely on detecting vulnerabilities as they occur in the eld, which can introduce a high performance overhead in production code. This paper describes a new approach for detecting injection vulnerabilities in applications by harnessing the combined power of human developers' test suites and automated dynamic analysis. Our new approach, R , monitors the execution of developerwritten functional tests in order to detect information ows that may be vulnerable to attack. Then, R uses a white-box test generation technique to repurpose those functional tests to check if any vulnerable ow could be exploited. When applied to the version of Apache Struts exploited in the 2017 Equifax attack, R quickly identi es the vulnerability, leveraging only the tests that existed in Struts at that time. We compared R to the state-ofthe-art static vulnerability detector Julia on benchmarks, nding that R outperformed Julia in both false positives and false negatives. We also used R to detect new vulnerabilities. CCS Concepts • Security and privacy → Vulnerability management; Web application security; • Software and its engineering → Software testing and debugging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP ApplicationsChanghua Luo, Penghui Li, Wei MengCCS 2022 · 被引用 27 次
- An Extensive Study on Adversarial Attack against Pre-trained Models of CodeXiaohu Du, Ming Wen, Zichao Wei, Shangwen Wang 等FSE 2023 · 被引用 21 次
- General Data Protection Runtime: Enforcing Transparent GDPR Compliance for Existing ApplicationsDavid Klein, Benny Rolle, Thomas Barber, Manuel Karl 等CCS 2023 · 被引用 5 次
- SQLiFuzz: Uncovering SQL Injection in Any Web ApplicationsI Putu Arya Dharmaadi, Van-Thuan Pham, Fadi Mohsen, Fatih TurkmenFSE 2026
- WHIP: Improving Static Vulnerability Detection in Web Application by Forcing tools to CollaborateFeras Al Kassar, Luca Compagna, Davide BalzarottiUSENIX Security 2023
它引用的顶会 Paper2
相关 Paper
- Argus: All your (PHP) Injection-sinks are belong to usRasoul Jahanshahi, Manuel EgeleUSENIX Security 2024 · 被引用 1 次
- CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web ApplicationsYichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo 等ICSE 2026
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang 等S&P 2024 · 被引用 15 次
- Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesErik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel 等S&P 2023
