Cerberus : Query-driven Scalable Security Checking for OAuth Service Provider Implementations

Cerberus : Query-driven Scalable Security Checking for OAuth Service Provider Implementations
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Tamjid Al Rahat
Tamjid Al Rahat
中科院分区:
其他
文献类型:
--
作者:
Tamjid Al Rahat

文献摘要

相似文献

OAuth 协议已被广泛采用,以简化第三方应用程序的用户身份验证和服务授权。然而,很少有人致力于自动检查服务提供商广泛使用的库的安全性。在本文中,我们正式确定了 OAuth 规范和安全最佳实践,并设计了 Cerberus(一种自动化静态分析器),以查找逻辑缺陷并识别 OAuth 服务提供程序库实现中的漏洞。为了有效检测服务提供商实施的大型代码库中的安全违规行为,Cerberus 采用查询驱动的算法来回答有关 OAuth 规范的查询。我们通过在拥有数百万下载量的流行 OAuth 库的数据集上对其进行评估来展示 Cerberus 的有效性。在这些备受瞩目的库中,Cerberus 已从 10 类逻辑缺陷中识别出 47 个漏洞,其中 24 个以前未知。我们得到了八个库的开发者的认可,并拥有三个被接受的 CVE。
OAuth protocols have been widely adopted to simplify user authentication and service authorization for third-party applications. However, little effort has been devoted to automatically checking the security of the libraries that service providers widely use. In this paper, we formalize the OAuth specifications and security best practices, and design Cerberus , an automated static analyzer, to find logical flaws and identify vulnerabilities in the implementation of OAuth service provider libraries. To efficiently detect security violations in a large codebase of service provider implementation, Cerberus employs a query-driven algorithm for answering queries about OAuth specifications. We demonstrate the effectiveness of Cerberus by evaluating it on datasets of popular OAuth libraries with millions of downloads. Among these high-profile libraries, Cerberus has identified 47 vulnerabilities from ten classes of logical flaws, 24 of which were previously unknown. We got acknowledged by the developers of eight libraries and had three accepted CVEs.