课题基金 / 基金详情

CAREER: Mining and Exploiting Web Vulnerabilities of Prototype-based Programming Languages via Object Property Graph

CAREER: Mining and Exploiting Web Vulnerabilities of Prototype-based Programming Languages via Object Property Graph
职业:通过对象属性图挖掘和利用基于原型的编程语言的 Web 漏洞
批准号:
2046361
负责人:
Yinzhi Cao
金额:
$56.05万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-06-01 至 2026-05-31

项目摘要

项目成果

Yinzhi Cao的其他基金

相似基金

相关文献

中文摘要
翻译
基于原型的语言,如一般的JavaScript或ECMAScript,是一种特殊类型的面向对象编程语言,它依赖于原型对象来获取新对象的初始属性。 这种编程语言广泛用于万维网(WWW),如Web浏览器扩展,服务器端Node.js应用程序和客户端脚本。虽然它们很受欢迎,并成功地改进了Web丰富的新功能,但与此同时,基于原型的语言也引入了新类型的对象相关漏洞。Web上此类对象相关漏洞的示例包括通过原型链污染对象属性的原型污染,以及篡改Web应用程序对象内部属性的内部属性篡改。现有的研究工作采用基于图的结构,如控制流图、数据流图和代码属性图,来表示目标计算机程序,有效地挖掘C/C++和PHP等语言中的漏洞。 然而,基于原型的语言,特别是上述对象相关的语言中的漏洞的检测仍然是具有挑战性的,仍然是未知的,在这个项目中,基于原型的语言的流,上下文,分支和路径敏感的抽象解释将被设计,实现和评估,以有效地检测和利用基于原型的语言,特别是JavaScript的漏洞。 抽象解释将生成一个特殊的图结构,称为对象属性图,以表示JavaScript对象,范围和变量作为节点,它们的关系作为边。对象属性图的优点是它可以通过抽象树和给定对象的所有属性有效地找到某些对象的定义和使用。 此外,所提出的对象属性图将不仅用于检测和利用JavaScript漏洞,而且还指导生成具有对象相关属性的附加JavaScript代码,以触发JavaScript引擎中的低级漏洞。该奖项反映了NSF的法定使命,并被认为是值得通过使用基金会的智力价值和更广泛的影响审查标准进行评估的支持。
英文摘要
Prototype-based languages, such as JavaScript or ECMAScript in general, are a special type of object-oriented programming languages that rely on a prototypical object to get the initial properties of a new object. Such programming languages are widely used in the World Wide Web (WWW), such as Web browser extensions, server-side Node.js applications, and client-side scripting. While they are popular and successful to improve the Web with abundant new functionalities, at the same time, prototype-based languages also introduce new types of object-related vulnerabilities. Examples of such object-related vulnerabilities on the Web are like prototype pollution that pollutes an object property via the prototypical chain, and internal property tampering that tampers an internal property of Web application objects. State-of-the-art works adopt graph-based structures, such as Control-flow Graph, Data-flow Graph and Code Property Graph, to represent target computer programs and efficiently mine vulnerabilities in languages like C/C++ and PHP. However, the detection of vulnerabilities in prototype-based languages, particularly the aforementioned object-related ones, is still challenging and remains unknown.In this project, a flow-, context-, branch- and path-sensitive abstract interpretation of prototype-based language will be designed, implemented and evaluated to efficiently detect and exploit vulnerabilities of prototype-based languages, particularly JavaScript. The abstract interpretation will generate a special graph structure, called Object Property Graph, to represent JavaScript objects, scopes, and variables as nodes and their relations as edges. The advantage of Object Property Graph is that it can efficiently find the definition and use of certain objects via Abstract Syntax Tree and all the properties of a given object. Furthermore, the proposed Object Property Graph will be used to not only detect and exploit JavaScript vulnerabilities but also guide the generation of additional JavaScript code with object-related properties to trigger low-level vulnerabilities in JavaScript engine. The investigator will involve undergraduates, women, K-12 students and minorities in the project.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: TCR: Transitioning Differentially Private Federated Learning to Enable Collaborative, Intelligent, Fair Skin Disease Diagnostics on Medical Imaging Cyberinfrastructure
  • 批准号:
    2319742
  • 项目类别:
    Standard Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2024
  • 负责人:
    Yinzhi Cao
  • 依托单位:
Collaborative Research: DASS: Assessing the Relationship Between Privacy Regulations and Software Development to Improve Rulemaking and Compliance
  • 批准号:
    2317185
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2023
  • 负责人:
    Yinzhi Cao
  • 依托单位:
SaTC: CORE: Small: Studying and Measuring the Consequence of Prototype Pollution Vulnerabilities Automatically via Joint Taintflow Analysis
  • 批准号:
    2154404
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2022
  • 负责人:
    Yinzhi Cao
  • 依托单位:
Collaborative Research: CNS Core: Medium: Cross-Layer Design of Video Analytics for the Internet of Things
  • 批准号:
    1955487
  • 项目类别:
    Standard Grant
  • 资助金额:
    $37.5万
  • 财政年份:
    2020
  • 负责人:
    Yinzhi Cao
  • 依托单位:
国内基金
海外基金
基于Genome mining技术研究抑制表皮葡萄球菌生物膜形成的次级代谢产物
  • 批准号:
    21242003
  • 项目类别:
    专项基金项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2012
  • 负责人:
    昌军
  • 依托单位: