Toward Understanding the Security Implications in Python Configuration Files
Xinwei Yu, Zhenkai Zhang, Yuzhe Tang, Xing Gao
摘要
Security incidents targeting open-source software have increased substantially in recent years, yet existing defenses primarily focus on analyzing source code while largely overlooking configuration files that define how software is built, installed, and executed. In this paper, we present an in-depth study of security risks in Python configuration files, analyzing five widely used formats across the project lifecycle. We focus on risks that exploit configuration files to silently redirect dependency resolution to attacker-controlled infrastructure or hijack benign commands. We design an automated framework and identify 39 configuration fields that can be exploited under realistic usage scenarios. We further demonstrate that existing malware detection tools fail to detect most of these risks. As mitigation, we develop ConfigScoper, which not only examines security-relevant fields but also employs multiple vulnerability detectors to identify potential malicious behaviors. We apply ConfigScoper in a measurement study analyzing millions of open-source Python projects on GitHub, and our empirical results show that exploitable risks already exist in real-world projects. Finally, we have responsibly disclosed the identified vulnerabilities to relevant stakeholders.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper27
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 被引用 91 次
- Practical Automated Detection of Malicious npm PackagesAdriana Sejfia, Max SchäferICSE 2022 · 被引用 65 次
- LastPyMile: identifying the discrepancy between sources and packagesDuc-Ly Vu, Fabio Massacci, Ivan Pashchenko, Henrik Plate 等FSE 2021 · 被引用 53 次
- Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downsEihal Alowaisheq, Peng Wang, Sumayah A. Alrwais, Xiaojing Liao 等NDSS 2019 · 被引用 48 次
相关 Paper
- Less is More? An Empirical Study on Configuration Issues in Python PyPI EcosystemYun Peng, Ruida Hu, Ruoke Wang, Cuiyun Gao 等ICSE 2024 · 被引用 5 次
- ConfTainter: Static Taint Analysis For Configuration OptionsTeng Wang, Haochen He, Xiaodong Liu, Shanshan Li 等ASE 2023 · 被引用 12 次
- An Empirical Study of Malicious Code In PyPI EcosystemWenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang 等ASE 2023 · 被引用 31 次
- Configuration smells in continuous delivery pipelines: a linter and a six-month study on GitLabCarmine Vassallo, Sebastian Proksch, Anna Jancso, Harald C. Gall 等FSE 2020 · 被引用 43 次
- ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at ScaleWenxin Jiang, Berk Çakar, Mikola Lysenko, James C DavisICSE 2026 · 被引用 2 次
