Counterfeit object-oriented programming vulnerabilities: an empirical study in Java

Counterfeit object-oriented programming vulnerabilities: an empirical study in Java
复制标题

DOI:
10.1145/3549035.3561183
复制
发表时间:
2022-11
期刊:
Proceedings of the 1st International Workshop on Mining Software Repositories Applications for Privacy and Security
影响因子:
--
通讯作者:
Joanna C. S. Santos;Xueling Zhang;Mehdi Mirakhorli
Joanna C. S. Santos;Xueling Zhang;Mehdi Mirakhorli
中科院分区:
其他
文献类型:
--
作者:
Joanna C. S. Santos;Xueling Zhang;Mehdi Mirakhorli

文献摘要

相似文献

许多现代应用程序依赖于面向对象(OO)设计原则,其中基本系统组件是对象和类。它们与其他进程共享对象,将它们存储在磁盘/文件中以供将来检索,或者通过网络将它们传输到其他系统。面向对象的程序利用了许多动态特性和设计原则,如运行时调度和面向对象的回调,从而允许灵活的软件设计。尽管这些功能看似无害,但攻击者可能会滥用这些功能,将程序的控制流劫持为不受欢迎的行为。这被称为伪造的面向对象编程(COOP),攻击者劫持程序中的对象,以便创建一系列引入恶意行为的方法调用。Coop是一种代码重用攻击,在这种攻击中,黑客劫持程序中的对象(小工具),并通过操纵在这些方法(小工具链)之间传递的方法和数据的序列来控制程序执行流。本文对非可信对象反序列化在实际软件系统中引起的Coop攻击进行了初步的经验研究。在这项初步研究中,我们调查了这些攻击的严重性、它们的后果,以及开发人员如何减轻它们。此外,我们使用这些发现创建了易受攻击的软件项目及其修复的数据集。
Many modern applications rely on Object-Oriented (OO) design principles, where the basic system components are objects and classes. They share objects with other processes, store them in disk/files for future retrieval or transport them over network to other systems. Object-oriented programs leverage numerous dynamic features and design principles such as runtime dispatching and object-oriented callbacks which allow flexible software design. Although seemingly innocuous, these features can be abused by the attackers to hijack the program's control flow to an undesirable behavior. This is referred to as Counterfeit Object-Oriented Programming (COOP), in which attackers hijack objects in the program in order to create a sequence of method calls that introduce a malicious behavior. COOP is a type of code reuse attack in which a hacker hijacks objects (gadgets) in the program and use that to control the program execution flow via manipulating the sequence of methods and data being passed among these methods (gadget chains). In this paper, we describe a preliminary empirical investigation of COOP attacks in real software systems caused by untrusted object deserialization. In this preliminary study, we investigated the severity of these attacks, their consequences, and how they were mitigated by developers. Furthermore, we used the findings to create a dataset of vulnerable software projects and their fixes.