SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata Learning
George Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis, Aggelos Kiayias
摘要
Finding differences between programs with similar functionality is an important security problem as such differences can be used for fingerprinting or creating evasion attacks against security software like Web Application Firewalls (WAFs) which are designed to detect malicious inputs to web applications. In this paper, we present SFADiff, a black-box differential testing framework based on Symbolic Finite Automata (SFA) learning. SFADiff can automatically find differences between a set of programs with comparable functionality. Unlike existing differential testing techniques, instead of searching for each difference individually, SFADiff infers SFA models of the target programs using black-box queries and systematically enumerates the differences between the inferred SFA models. All differences between the inferred models are checked against the corresponding programs. Any difference between the models, that does not result in a difference between the corresponding programs, is used as a counterexample for further refinement of the inferred models. SFADiff's model-based approach, unlike existing differential testing tools, also support fully automated root cause analysis in a domain-independent manner. We evaluate SFADiff in three different settings for finding discrepancies between: (i) three TCP implementations, (ii) four WAFs, and (iii) HTML/JavaScript parsing implementations in WAFs and web browsers. Our results demonstrate that SFADiff is able to identify and enumerate the differences systematically and efficiently in all these settings. We show that SFADiff is able to find differences not only between different WAFs but also between different versions of the same WAF. SFADiff is also able to discover three previously-unknown differences between the HTML/Java-Script parsers of two popular WAFs (PHPIDS 0.7 and Expose 2.4.0) and the corresponding parsers of Google Chrome, Firefox, Safari, and Internet Explorer. We confirm that all these differences can be used to evade the WAFs and launch successful cross-site scripting attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- NEZHA: Efficient Domain-Independent Differential TestingTheofilos Petsios, Adrian Tang, Salvatore J. Stolfo, Angelos D. Keromytis 等S&P 2017 · 被引用 132 次
- HVLearn: Automated Black-Box Analysis of Hostname Verification in SSL/TLS ImplementationsSuphannee Sivakorn, George Argyros, Kexin Pei, Angelos D. Keromytis 等S&P 2017 · 被引用 88 次
- SymCerts: Practical Symbolic Execution for Exposing Noncompliance in X.509 Certificate Validation ImplementationsSze Yiu Chau, Omar Chowdhury, Md. Endadul Hoque, Huangyi Ge 等S&P 2017 · 被引用 67 次
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 被引用 57 次
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury 等CCS 2021 · 被引用 41 次
它引用的顶会 Paper2
相关 Paper
- ZendDiff: Differential Testing of PHP InterpreterYuancheng Jiang, Jianing Wang, Qiange Liu, Yeqi Fu 等ASE 2025 · 被引用 1 次
- Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application FirewallsQi Wang, Jianjun Chen, Zheyu Jiang, Run Guo 等S&P 2024 · 被引用 11 次
- SBDT: Search-Based Differential Testing of Certificate Parsers in SSL/TLS ImplementationsChu Chen, Pinghong Ren, Zhenhua Duan, Cong Tian 等ISSTA 2023 · 被引用 13 次
- HyDiff: hybrid differential software analysisYannic Noller, Corina S. Pasareanu, Marcel Böhme, Youcheng Sun 等ICSE 2020 · 被引用 37 次
- SEDiff: scope-aware differential fuzzing to test internal function models in symbolic executionPenghui Li, Wei Meng, Kangjie LuFSE 2022 · 被引用 3 次
