Revealing Injection Vulnerabilities by Leveraging Existing Tests

Revealing Injection Vulnerabilities by Leveraging Existing Tests
复制标题

DOI:
10.1145/3377811.3380326
复制
发表时间:
2020-06
期刊:
2020 IEEE/ACM 42nd International Conference on Software Engineering (ICSE)
影响因子:
--
通讯作者:
Katherine Hough;G. B. Welearegai;Christian Hammer;Jonathan Bell
Katherine Hough;G. B. Welearegai;Christian Hammer;Jonathan Bell
中科院分区:
其他
文献类型:
--
作者:
Katherine Hough;G. B. Welearegai;Christian Hammer;Jonathan Bell

文献摘要

被引文献

相似文献

代码注入攻击(如 2017 年备受瞩目的 Equifax 外泄事件中使用的代码注入攻击)已变得越来越常见,目前在 OWASP 的关键网络应用程序漏洞列表中排名第一。用于检测这些漏洞的静态分析可能会出现假阳性报告,让开发人员不知所措。同时,大多数动态分析依赖于检测现场出现的漏洞,这会给生产代码带来很高的性能开销。本文介绍了一种利用人类开发人员的测试套件和自动动态分析的综合能力来检测应用程序中注入漏洞的新方法。我们的新方法 Rivulet 可监控开发人员编写的功能测试的执行情况,以检测可能易受攻击的信息流。然后,Rivulet 使用白盒测试生成技术重新利用这些功能测试,检查是否有任何易受攻击的信息流可被利用。当应用到 2017 年 Equifax 攻击事件中被利用的 Apache Struts 版本时,Rivulet 仅利用了当时 Struts 中存在的测试,就迅速识别出了漏洞。我们在基准测试中将 Rivulet 与最先进的静态漏洞检测器 Julia 进行了比较,发现 Rivulet 在误报和漏报方面都优于 Julia。我们还使用 Rivulet 检测了新的漏洞。
Code injection attacks, like the one used in the high-profile 2017 Equifax breach, have become increasingly common, now ranking #1 on OWASP's list of critical web application vulnerabilities. Static analyses for detecting these vulnerabilities can overwhelm developers with false positive reports. Meanwhile, most dynamic analyses rely on detecting vulnerabilities as they occur in the field, which can introduce a high performance overhead in production code. This paper describes a new approach for detecting injection vulnerabilities in applications by harnessing the combined power of human developers' test suites and automated dynamic analysis. Our new approach, Rivulet, monitors the execution of developer-written functional tests in order to detect information flows that may be vulnerable to attack. Then, Rivulet uses a white-box test generation technique to repurpose those functional tests to check if any vulnerable flow could be exploited. When applied to the version of Apache Struts exploited in the 2017 Equifax attack, Rivulet quickly identifies the vulnerability, leveraging only the tests that existed in Struts at that time. We compared Rivulet to the state-of-the-art static vulnerability detector Julia on benchmarks, finding that Rivulet outperformed Julia in both false positives and false negatives. We also used Rivulet to detect new vulnerabilities.