Detecting Broken Object-Level Authorization Vulnerabilities in Database-Backed Applications
Yongheng Huang, Chenghang Shi, Jie Lu, Haofeng Li, Haining Meng, Lian Li
摘要
Broken object-level authorization (BOLA) vulnerabilities are among the most critical security risks facing database-backed applications. However, there is still a significant gap in our systematic understanding of these vulnerabilities. To bridge this gap, we conducted an in-depth study of 101 real-world BOLA vulnerabilities from opensource applications. Our study revealed the four most common object-level authorization models in database-backed application.
The insights gained from our study inspired the development of a new tool called BolaRay. This tool employs a combination of SQL and static analysis to automatically infer the distinct types of object-level authorization models, and subsequently verify whether existing implementations enforce appropriate checks for these models. We evaluated BolaRay using 25 popular database-backed applications, which led to the identification of 193 true vulnerabilities, including 178 vulnerabilities that have never been reported before, at a false positive rate of 21.86%. We reported all newly identified vulnerabilities to the corresponding maintainers. To date, 155 vulnerabilities have been confirmed, with 52 CVE IDs granted.
• Security and privacy → Software and application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web ApplicationsQiyi Zhang, Fengyu Liu, Zihan Lin, Yuan ZhangCCS 2025
- BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Enhao Li, Wei Meng 等CCS 2025
- VulPA: Detecting Semantically Recurring Vulnerabilities with Multi-object Typestate AnalysisLiqing Cao, Haofeng Li, Chenghang Shi, Jie Lu 等FSE 2025
它引用的顶会 Paper15
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 被引用 85 次
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung 等USENIX Security 2019 · 被引用 77 次
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 被引用 59 次
- TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP ApplicationsChanghua Luo, Penghui Li, Wei MengCCS 2022 · 被引用 27 次
- Protecting Data Integrity of Web Applications with Database Constraints Inferred from Application CodeHaochen Huang, Bingyu Shen, Li Zhong, Yuanyuan ZhouASPLOS 2023 · 被引用 16 次
相关 Paper
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 被引用 99 次
- Beacon: Detecting Broken Access Control Vulnerabilities in DBMSs via System Catalog Consistency ValidationZongrui Peng, Jingzhou Fu, Zhiyong Wu, Jie Liang 等OOPSLA 2026
- Be Careful of What You Embed: Demystifying OLE VulnerabilitiesYunpeng Tian, Feng Dong, Haoyi Liu, Meng Xu 等NDSS 2025
- MOCGuard: Automatically Detecting Missing-Owner-Check Vulnerabilities in Java Web ApplicationsFengyu Liu, Youkun Shi, Yuan Zhang, Guangliang Yang 等S&P 2025
- Cerberus: Query-driven Scalable Vulnerability Detection in OAuth Service Provider ImplementationsTamjid Al Rahat, Yu Feng, Yuan TianCCS 2022 · 被引用 12 次
