UChecker: Automatically Detecting PHP-Based Unrestricted File Upload Vulnerabilities

UChecker: Automatically Detecting PHP-Based Unrestricted File Upload Vulnerabilities
复制标题

DOI:
10.1109/dsn.2019.00064
复制
发表时间:
2019-06
期刊:
2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Jin Huang;Yu Li;Junjie Zhang;Rui Dai
Jin Huang;Yu Li;Junjie Zhang;Rui Dai
中科院分区:
其他
文献类型:
--
作者:
Jin Huang;Yu Li;Junjie Zhang;Rui Dai

文献摘要

被引文献

相似文献

不受限制的文件上传漏洞使攻击者能够在Web服务器中上传和执行恶意脚本。我们已经建立了一个系统,即Uplink,有效地和自动地检测PHP服务器端Web应用程序中的此类漏洞。为了达到这个目的,Udash首先解释程序源代码的抽象语法树(AST)来执行符号执行。然后使用SMT约束对漏洞进行建模,并进一步利用SMT求解器来验证这些约束的可满足性。UCNET的特点是一种新的面向可扩展性的局部性分析算法,以减少符号执行的工作量,一个AST驱动的符号执行引擎,具有紧凑的数据结构,和规则,以翻译为基于PHP的约束基于SMT的约束,通过减轻他们的语义差距。基于真实世界的例子的实验表明,Udash已经完成了较高的检测精度。此外,它还检测到三个以前未知的易受攻击的PHP脚本。
Unrestricted file upload vulnerabilities enable attackers to upload and execute malicious scripts in web servers. We have built a system, namely UChecker, to effectively and automatically detect such vulnerabilities in PHP server-side web applications. Towards this end, UChecker first interprets abstract syntax trees (AST) of program source code to perform symbolic execution. It then models vulnerabilities using SMT constraints and further leverages an SMT solver to verify the satisfiability of these constraints. UChecker features a novel vulnerability-oriented locality analysis algorithm to reduce the workload of symbolic execution, an AST-driven symbolic execution engine with compact data structures, and rules to translate PHP-based constraints into SMT-based constraints by mitigating their semantic gaps. Experiments based on real-world examples have demonstrated that UChecker has accomplished a high detection accuracy. In addition, it detected three vulnerable PHP scripts that are previously unknown.