Automatic Detection and Repair of Input Validation and Sanitization Bugs

Automatic Detection and Repair of Input Validation and Sanitization Bugs
复制标题

自动检测和修复输入验证和清理错误

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
Muath Alkhalaf
Muath Alkhalaf
中科院分区:
--
文献类型:
--
作者:
Muath Alkhalaf

文献摘要

被引文献

相似文献

作者:Alkhalaf, Muath |顾问:Bultan, Tevfik |摘要:开发可靠的 Web 应用程序的一个关键问题是输入验证和清理的正确性。用于验证和清理的字符串操作操作中的错误很常见,导致错误的应用程序行为和可被恶意用户利用的漏洞。在本论文中,我们研究了在客户端(JavaScript)和服务器端(PHP 或 Java)代码中自动检测和修复验证和清理错误的问题。我们首先提出了输入验证和清理功能的形式模型以及新的领域特定中间语言来表示它们。然后,我们展示如何从 Web 应用程序中的客户端和服务器端代码中提取中间语言的输入验证和清理函数。在提取阶段之后,我们使用基于自动机的静态字符串分析技术来自动验证和修复提取的函数。我们的贡献之一是开发了高效的基于自动机的字符串分析技术,用于频繁使用的复杂字符串操作。我们开发了两种基本的错误检测和修复方法:1)基于策略,2)差分。在基于策略的方法中,输入验证和清理策略使用两个正则表达式来表达,一个指定最大策略(应允许的字符串集的上限),另一个指定最小策略(应允许的字符串集的下限)。使用我们的字符串分析技术,我们可以识别输入验证和清理函数中的两种类型的错误:1)它接受最大策略不允许的一组字符串(即,它是约束不足的),或者2)它拒绝最小策略允许的一组字符串(即,它是过度约束的)。我们的差异错误检测和修复方法不需要任何策略规范。它利用了这样一个事实:在 Web 应用程序中,开发人员通常在客户端和服务器端执行冗余输入验证和清理,因为客户端检查可以被绕过。使用基于自动机的字符串分析,我们比较从客户端和服务器端代码中提取的输入验证和清理功能,并识别和报告它们之间的不一致。最后,我们提出了一种自动差异修复技术,可以修复彼此之间或跨应用程序的客户端和服务器端代码,以加强验证和清理检查。给定参考和目标函数,我们的差异修复技术通过自动生成一组补丁,基于参考函数加强目标函数中的验证和清理操作。我们对许多现实世界的Web应用程序进行了实验,发现了许多错误和漏洞。我们的分析生成反例行为,展示检测到的错误和漏洞,以帮助开发人员进行调试过程。此外,我们会自动生成补丁,可用于缓解检测到的错误和漏洞,直到开发人员编写自己的补丁。
Author(s): Alkhalaf, Muath | Advisor(s): Bultan, Tevfik | Abstract: A crucial problem in developing dependable web applications is thecorrectness of the input validation and sanitization. Bugs in stringmanipulation operations used for validation and sanitization are common,resulting in erroneous application behavior and vulnerabilities that areexploitable by malicious users. In this dissertation, we investigate theproblem of automatic detection and repair of validation and sanitization bugsboth at the client-side (JavaScript) and the server-side (PHP or Java) code.We first present a formal model for input validation and sanitizationfunctions along with a new domain specific intermediate languageto represent them. Then, we show how to extract input validation andsanitization functions in our intermediate language from both client andserver-side code in web applications. After the extraction phase, we useautomata-based static string-analysis techniques to automatically verifyand fix the extracted functions. One of our contributions is the developmentof efficient automata-based string analysis techniques for frequently used,complex string operations.We developed two basic approaches to bug detection and repair: 1)policy-based, and 2) differential. In the policy-based approach, inputvalidation and sanitization policies are expressed using two regularexpressions, one specifying the maximum policy (the upper bound for theset of strings that should be allowed) and the other specifying the minimumpolicy (the lower bound for the set of strings that should be allowed). Usingour string analysis techniques we can identify two types of errors inan input validation and sanitization function: 1) it accepts a set of strings thatis not permitted by the maximum policy (i.e., it is under-constrained),or 2) it rejects a set of strings that is permitted by the minimum policy(i.e., it is over-constrained).Our differential bug detection and repair approach does not require anypolicy specifications. It exploits the fact that, in web applications,developers typically perform redundant input validation and sanitizationin both the client and the server-side since client-side checks canbe by-passed. Using automata-based string analysis, we compare theinput validation and sanitization functions extracted from the client- andserver-side code, and identify and report the inconsistencies between them.Finally, we present an automated differential repair technique that canrepair client and server-side code with respect to each other, or acrossapplications in order to strengthen the validation and sanitizationchecks. Given a reference and a target function, our differential repairtechnique strengthens the validation and sanitization operations in thetarget function based on the reference function by automatically generatinga set of patches.We experimented with a number of real world web applications and found manybugs and vulnerabilities. Our analysis generates counter-example behaviorsdemonstrating the detected bugs and vulnerabilities to help the developerswith the debugging process. Moreover, we automatically generate patchesthat can be used to mitigate the detected bugs and vulnerabilities untildevelopers write their own patches.