ShanghaiTech University Knowledge Management System
Whether We Are Good Enough to Detect Server-Side Request Forgeries in PHP-native Applications? | |
2024 | |
会议录名称 | PROCEEDINGS OF THE 2024 ON ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY |
页码 | 4928-4930 |
发表状态 | 已发表 |
DOI | 10.1145/3658644.3691419 |
摘要 | Server-side request forgeries (SSRFs) are inevitable in PHP web applications. Existing static taint analysis tools for PHP suffer from both high rates of false positives and false negatives in detecting SSRF because they do not incorporate application-specific sources and sinks, account for PHP's dynamic type characteristics, and include SSRF-specific taint analysis rules, leading to over-tainting and under-tainting. In this work, we propose a technique to accurately detect SSRF vulnerabilities in PHP web applications. First, we extract both PHP built-in and application-specific functions as candidate source and sink functions. Second, we extract explicit and implicit function calls to construct applications' call graphs. Third, we perform a taint analysis based on a set of rules that prevent over-tainting and under-tainting. We have implemented a prototype and evaluated it with different types of PHP web applications. Our preliminary experiment shows that we detect 24 SSRF vulnerabilities in 13 different types of applications. 20 of the vulnerabilities are known and 4 of the vulnerabilities are new. |
会议录编者/会议主办者 | ACM |
关键词 | PHP Server-Side Request Forgery Taint Analysis |
会议名称 | ACM SIGSAC Conference on Computer and Communications Security |
出版地 | 美国 |
会议地点 | Salt Lake City, UT, USA |
会议日期 | 2024年10月14日-18日 |
学科门类 | 工学::计算机科学与技术(可授工学、理学学位) |
URL | 查看原文 |
收录类别 | CPCI-S |
语种 | 英语 |
资助项目 | Shanghai Sailing Program[22YF1428600] ; National Natural Science Foundation of China[62202306] |
WOS研究方向 | Computer Science ; Telecommunications |
WOS类目 | Computer Science, Artificial Intelligence ; Computer Science, Hardware & Architecture ; Computer Science, Theory & Methods ; Telecommunications |
WOS记录号 | WOS:001436367300352 |
出版者 | ASSOC COMPUTING MACHINERY |
文献类型 | 会议论文 |
条目标识符 | https://kms.shanghaitech.edu.cn/handle/2MSLDSTB/503651 |
专题 | 信息科学与技术学院_硕士生 信息科学与技术学院_PI研究组_唐宇田组 信息科学与技术学院_PI研究组_何静竹组 |
通讯作者 | He, Jingzhu |
作者单位 | 1.上海科技大学 2.IBM Research 3.University of Glasgow |
第一作者单位 | 上海科技大学 |
通讯作者单位 | 上海科技大学 |
第一作者的第一单位 | 上海科技大学 |
推荐引用方式 GB/T 7714 | Ji, Yuchen,Dai, Ting,Tang, Yutian,et al. Whether We Are Good Enough to Detect Server-Side Request Forgeries in PHP-native Applications?[C]//ACM. 美国:ASSOC COMPUTING MACHINERY,2024:4928-4930. |
条目包含的文件 | ||||||
文件名称/大小 | 文献类型 | 版本类型 | 开放类型 | 使用许可 |
修改评论
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。