首页> 外文会议>Australasian conference on information security and privacy >Practical Dynamic Taint Tracking for Exploiting Input Sanitization Error in Java Applications
【24h】

Practical Dynamic Taint Tracking for Exploiting Input Sanitization Error in Java Applications

机译:实用的动态污点跟踪,用于利用Java应用程序中的输入清理错误

获取原文

摘要

Errors in the sanitization of user inputs lead to serious security vulnerabilities. Many applications contain such errors, making them vulnerable to input sanitization exploits. Therefore, internet worms via exploiting vulnerabilities in applications infect hundreds of thousands of users in a matter of short time, causing hundreds of millions of dollars in damages. To successfully counter internet worm attacks, we need automatic detection and defense mechanisms. First, we need automatic detection mechanisms that can detect runtime attacks for vulnerabilities. A disclosure mechanism should be simple to deploy, resulting in few false positives and few false negatives. In this paper we present Tainer, an automatic dynamic taint analysis framework to detect and generate exploits for sanitization based vulnerabilities for Java web applications. Particularly, our method is based on tracking the flow of taint information from untrusted input the application sensitive methods (such as console, file, network, database or another program). Our proposed framework is portable, quick, accurate, and does not need the source code of applications. We demonstrate the usefulness of the framework by detecting several zero-day actual vulnerabilities in popular Java applications.
机译:用户输入清理中的错误会导致严重的安全漏洞。许多应用程序包含此类错误,使它们容易受到输入清理漏洞的攻击。因此,蠕虫通过利用应用程序中的漏洞在短时间内感染了成千上万的用户,造成了数亿美元的损失。为了成功应对Internet蠕虫攻击,我们需要自动检测和防御机制。首先,我们需要能够检测漏洞的运行时攻击的自动检测机制。公开机制应易于部署,从而导致很少的误报和很少的误报。在本文中,我们介绍了Tainer,这是一个自动的动态污点分析框架,用于检测和生成针对Java Web应用程序基于清理的漏洞的攻击。特别是,我们的方法是基于跟踪来自不信任输入的污点信息流的,这些输入是应用程序敏感的方法(例如控制台,文件,网络,数据库或其他程序)。我们提出的框架可移植,快速,准确,并且不需要应用程序的源代码。通过检测流行的Java应用程序中的几个零日实际漏洞,我们证明了该框架的有用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号