Whether We Are Good Enough to Detect Server-Side Request Forgeries in PHP-native Applications?
2024
会议录名称PROCEEDINGS OF THE 2024 ON ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY
页码4928-4930
发表状态已发表
DOI10.1145/3658644.3691419
摘要

Server-side request forgeries (SSRFs) are inevitable in PHP web applications. Existing static taint analysis tools for PHP suffer from both high rates of false positives and false negatives in detecting SSRF because they do not incorporate application-specific sources and sinks, account for PHP's dynamic type characteristics, and include SSRF-specific taint analysis rules, leading to over-tainting and under-tainting. In this work, we propose a technique to accurately detect SSRF vulnerabilities in PHP web applications. First, we extract both PHP built-in and application-specific functions as candidate source and sink functions. Second, we extract explicit and implicit function calls to construct applications' call graphs. Third, we perform a taint analysis based on a set of rules that prevent over-tainting and under-tainting. We have implemented a prototype and evaluated it with different types of PHP web applications. Our preliminary experiment shows that we detect 24 SSRF vulnerabilities in 13 different types of applications. 20 of the vulnerabilities are known and 4 of the vulnerabilities are new.

会议录编者/会议主办者ACM
关键词PHP Server-Side Request Forgery Taint Analysis
会议名称ACM SIGSAC Conference on Computer and Communications Security
出版地美国
会议地点Salt Lake City, UT, USA
会议日期2024年10月14日-18日
学科门类工学::计算机科学与技术(可授工学、理学学位)
URL查看原文
收录类别CPCI-S
语种英语
资助项目Shanghai Sailing Program[22YF1428600] ; National Natural Science Foundation of China[62202306]
WOS研究方向Computer Science ; Telecommunications
WOS类目Computer Science, Artificial Intelligence ; Computer Science, Hardware & Architecture ; Computer Science, Theory & Methods ; Telecommunications
WOS记录号WOS:001436367300352
出版者ASSOC COMPUTING MACHINERY
文献类型会议论文
条目标识符https://kms.shanghaitech.edu.cn/handle/2MSLDSTB/503651
专题信息科学与技术学院_硕士生
信息科学与技术学院_PI研究组_唐宇田组
信息科学与技术学院_PI研究组_何静竹组
通讯作者He, Jingzhu
作者单位
1.上海科技大学
2.IBM Research
3.University of Glasgow
第一作者单位上海科技大学
通讯作者单位上海科技大学
第一作者的第一单位上海科技大学
推荐引用方式
GB/T 7714
Ji, Yuchen,Dai, Ting,Tang, Yutian,et al. Whether We Are Good Enough to Detect Server-Side Request Forgeries in PHP-native Applications?[C]//ACM. 美国:ASSOC COMPUTING MACHINERY,2024:4928-4930.
条目包含的文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可
个性服务
查看访问统计
谷歌学术
谷歌学术中相似的文章
[Ji, Yuchen]的文章
[Dai, Ting]的文章
[Tang, Yutian]的文章
百度学术
百度学术中相似的文章
[Ji, Yuchen]的文章
[Dai, Ting]的文章
[Tang, Yutian]的文章
必应学术
必应学术中相似的文章
[Ji, Yuchen]的文章
[Dai, Ting]的文章
[Tang, Yutian]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。