Business-Layer Session Puzzling Racer: Dynamic Security Testing Against Session Puzzling Race Conditions in Business Layer

被引:2
作者
Alidoosti, Mitra [1 ]
Nowroozi, Alireza [2 ]
Nickabadi, Ahmad [3 ]
机构
[1] Malek Ashtar Univ Tehran, Tehran, Iran
[2] IRIB Univ Tehran, Tehran, Iran
[3] Amirkabir Univ Tehran, Tehran, Iran
来源
ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY | 2022年 / 14卷 / 01期
关键词
Dynamic Testing; Vulnerability Analysis; Web Application; Business Process; Race Condition; LOGIC VULNERABILITIES;
D O I
10.22042/isecure.2021.272808.637
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Parallel execution of multiple threads of a web application will result in server-side races if the web application is not synchronized correctly. Server-side race is susceptible to flaws in the relation between the server and the database. Detecting the race condition in the web applications depends on the business logic of the application. No logic-aware approach has been presented to deal with race conditions. Furthermore, most existing approaches either result in DoS or are not applicable with false positive. In this study, the session puzzling race conditions existing in a web application are classified and described. In addition, we present Business-Layer Session Puzzling Racer, a black-box approach for dynamic application security testing, to detect the business-layer vulnerability of the application against session puzzling race conditions. Experiments on well-known and widely used web applications showed that Business-Layer Session Puzzling Racer is able to detect the business layer vulnerabilities of these applications against race conditions. In addition, the amount of traffic generated to identify the vulnerabilities has been improved by about 94.38% by identifying the business layer of the application. Thus, Business-Layer Session Puzzling Racer does not result in DoS. (C) 2020 ISC. All rights reserved.
引用
收藏
页码:83 / 104
页数:22
相关论文
共 43 条
[1]  
Abbott R., 1976, SECURITY ANAL ENHANC
[2]   Practical initialization race detection for JavaScript web applications [J].
Adamsen, Christoffer Quist ;
Méller, Anders ;
Tip, Frank .
Proceedings of the ACM on Programming Languages, 2017, 1 (OOPSLA)
[3]   Repairing Event Race Errors by Controlling Nondeterminism [J].
Adamsen, Christoffer Quist ;
Moller, Anders ;
Karim, Rezwana ;
Sridharan, Manu ;
Tip, Frank ;
Sen, Koushik .
2017 IEEE/ACM 39TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE), 2017, :289-299
[4]  
Adamsen CQ., 2018, P 2018 26 ACM JOINT
[5]  
ADVE SV, 1991, ACM COMP AR, V19, P234, DOI 10.1145/115953.115976
[6]  
Alidoosti M., 2019, J. Comput. Secur., V6, P65, DOI DOI 10.22108/JCS.2020.117223.1028
[7]  
Alidoosti M, 2018, INT ISC CONF INFO SE
[8]   Evaluating the web-application resiliency to business-layer DoS attacks [J].
Alidoosti, Mitra ;
Nowroozi, Alireza ;
Nickabadi, Ahmad .
ETRI JOURNAL, 2020, 42 (03) :433-445
[9]  
Bishop M, 1996, COMPUT SYST, V9, P131
[10]  
CERT, 2002, ADV CA 2000 02 MAL H