Lua Code: Security Overview and Practical Approaches to Static Analysis

Lua Code: Security Overview and Practical Approaches to Static Analysis
复制标题

DOI:
10.1109/spw.2017.38
复制
发表时间:
2017-05
期刊:
2017 IEEE Security and Privacy Workshops (SPW)
影响因子:
--
通讯作者:
Andrei Costin
Andrei Costin
中科院分区:
其他
文献类型:
--
作者:
Andrei Costin

文献摘要

被引文献

相似文献

Lua是一种解释型、跨平台、可嵌入、高性能和低占用的语言。Lua的受欢迎程度在过去几年中不断上升。简单的设计和高效的资源使用,再加上其性能,使其对生产Web应用程序具有吸引力,甚至对维基百科,CloudFlare和GitHub等大型组织也是如此。除此之外,Lua是嵌入式和物联网设备编程的首选之一。这个上下文允许假设一个大的和不断增长的Lua代码库还有待评估。这种不断增长的Lua代码库可能会驱动生产服务器和大量设备,其中一些可能具有关键任务功能,例如汽车或家庭自动化领域。然而,与其他日益流行的语言(如PHP、Python和JavaScript)相比,Lua明显缺乏静态分析工具和易受攻击的代码语料库。即使是最先进的支持几十种语言和技术的商业工具,实际上也不支持Lua静态代码分析。在本文中,我们提出了第一个公共的静态安全测试分析(SAST)工具,用于Lua代码,目前专注于Web漏洞。我们展示了它的潜力与良好的和有前途的初步结果,我们获得了简单的和故意脆弱的Lua代码样本,我们合成我们的实验。我们还展示并发布了我们故意脆弱的Lua代码的合成语料库,以及我们实验中使用的虚拟和完全可复制环境形式的测试设置。我们希望我们的工作能够激发人们对语言安全和静态分析这一明显被忽视的领域的新的兴趣,并激励社区为这些开源项目做出贡献。该工具、示例和测试VM设置将在http://lua.re和http://lua.rocks上发布和更新。
Lua is an interpreted, cross-platform, embeddable, performant and low-footprint language. Lua's popularity is on the rise in the last couple of years. Simple design and efficient usage of resources combined with its performance make it attractive for production web applications even to big organizations such as Wikipedia, CloudFlare and GitHub. In addition to this, Lua is one of the preferred choices for programming embedded and IoT devices. This context allows to assume a large and growing Lua codebase yet to be assessed. This growing Lua codebase could be potentially driving production servers and extremely large number of devices, some perhaps with mission-critical function for example in automotive or home-automation domains. However, there is a substantial and obvious lack of static analysis tools and vulnerable code corpora for Lua as compared to other increasingly popular languages, such as PHP, Python and JavaScript. Even the state-of-the-art commercial tools that support dozens of languages and technologies actually do not support Lua static code analysis. In this paper we present the first public Static Analysis for Security Testing (SAST) tool for Lua code that is currently focused on web vulnerabilities. We show its potential with good and promising preliminary results that we obtained on simple and intentionally vulnerable Lua code samples that we synthesized for our experiments. We also present and release our synthesized corpus of intentionally vulnerable Lua code, as well as the testing setups used in our experiments in form of virtual and completely reproducible environments. We hope our work can spark additional and renewed interest in this apparently overlooked area of language security and static analysis, as well as motivate community's contribution to these open-source projects. The tool, the samples and the testing VM setups will be released and updated at http://lua.re and http://lua.rocks.