Academic Journal
Analyzing and Discovering Spatial Algorithm Complexity Vulnerabilities in Recursion.
| Title: | Analyzing and Discovering Spatial Algorithm Complexity Vulnerabilities in Recursion. |
|---|---|
| Authors: | Wang, Ziqi, Bu, Debao, Tian, Weihan, Cui, Baojiang |
| Source: | Applied Sciences (2076-3417); Mar2024, Vol. 14 Issue 5, p1855, 19p |
| Subject Terms: | Denial of service attacks, Algorithms |
| Abstract: | The algorithmic complexity vulnerability (ACV) that may lead to denial of service attacks greatly disrupts the security and availability of applications, and due to the widespread use of third-party libraries, its impact may be amplified through the software supply chain. The existing work in the field is dedicated to abstract loop or iterative patterns and fuzzing the entire application to discover algorithm complexity vulnerabilities, but they still face efficiency and effectiveness issues. Our research focuses on: (1) proposing a representation and extraction method for code features related to algorithmic complexity vulnerabilities, helping analysts quickly understand program logic; (2) providing a new ACV detecting model, focusing on the spatial complexity anomalies caused by deep recursion structures, and proposing a new filtering method; and (3) aiming at the difficulty of efficiently generating complex-data-type-related payloads using existing symbol execution techniques, a call-chain-guided payload construction method is proposed. We tested third-party components in the open-source Java Maven Repository, identified many unexposed vulnerabilities, and eight of them received Common Vulnerabilities and Exposures (CVE) identifiers, and demonstrated that our method can discover more algorithmic complexity vulnerabilities compared to existing tools with better performance. [ABSTRACT FROM AUTHOR] |
| Copyright of Applied Sciences (2076-3417) is the property of MDPI and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Complementary Index |
| FullText | Text: Availability: 0 CustomLinks: – Url: https://resolver.ebsco.com/c/fiv2js/result?sid=EBSCO:edb&genre=article&issn=20763417&ISBN=&volume=14&issue=5&date=20240301&spage=1855&pages=1855-1873&title=Applied Sciences (2076-3417)&atitle=Analyzing%20and%20Discovering%20Spatial%20Algorithm%20Complexity%20Vulnerabilities%20in%20Recursion.&aulast=Wang%2C%20Ziqi&id=DOI:10.3390/app14051855 Name: Full Text Finder (for New FTF UI) (ns324271) Category: fullText Text: Full Text Finder MouseOverText: Full Text Finder |
|---|---|
| Header | DbId: edb DbLabel: Complementary Index An: 175987908 RelevancyScore: 958 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 957.825012207031 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Analyzing and Discovering Spatial Algorithm Complexity Vulnerabilities in Recursion. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Wang%2C+Ziqi%22">Wang, Ziqi</searchLink><br /><searchLink fieldCode="AR" term="%22Bu%2C+Debao%22">Bu, Debao</searchLink><br /><searchLink fieldCode="AR" term="%22Tian%2C+Weihan%22">Tian, Weihan</searchLink><br /><searchLink fieldCode="AR" term="%22Cui%2C+Baojiang%22">Cui, Baojiang</searchLink> – Name: TitleSource Label: Source Group: Src Data: Applied Sciences (2076-3417); Mar2024, Vol. 14 Issue 5, p1855, 19p – Name: Subject Label: Subject Terms Group: Su Data: <searchLink fieldCode="DE" term="%22Denial+of+service+attacks%22">Denial of service attacks</searchLink><br /><searchLink fieldCode="DE" term="%22Algorithms%22">Algorithms</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: The algorithmic complexity vulnerability (ACV) that may lead to denial of service attacks greatly disrupts the security and availability of applications, and due to the widespread use of third-party libraries, its impact may be amplified through the software supply chain. The existing work in the field is dedicated to abstract loop or iterative patterns and fuzzing the entire application to discover algorithm complexity vulnerabilities, but they still face efficiency and effectiveness issues. Our research focuses on: (1) proposing a representation and extraction method for code features related to algorithmic complexity vulnerabilities, helping analysts quickly understand program logic; (2) providing a new ACV detecting model, focusing on the spatial complexity anomalies caused by deep recursion structures, and proposing a new filtering method; and (3) aiming at the difficulty of efficiently generating complex-data-type-related payloads using existing symbol execution techniques, a call-chain-guided payload construction method is proposed. We tested third-party components in the open-source Java Maven Repository, identified many unexposed vulnerabilities, and eight of them received Common Vulnerabilities and Exposures (CVE) identifiers, and demonstrated that our method can discover more algorithmic complexity vulnerabilities compared to existing tools with better performance. [ABSTRACT FROM AUTHOR] – Name: Abstract Label: Group: Ab Data: <i>Copyright of Applied Sciences (2076-3417) is the property of MDPI and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edb&AN=175987908 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.3390/app14051855 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 19 StartPage: 1855 Subjects: – SubjectFull: Denial of service attacks Type: general – SubjectFull: Algorithms Type: general Titles: – TitleFull: Analyzing and Discovering Spatial Algorithm Complexity Vulnerabilities in Recursion. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Wang, Ziqi – PersonEntity: Name: NameFull: Bu, Debao – PersonEntity: Name: NameFull: Tian, Weihan – PersonEntity: Name: NameFull: Cui, Baojiang IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 03 Text: Mar2024 Type: published Y: 2024 Identifiers: – Type: issn-print Value: 20763417 Numbering: – Type: volume Value: 14 – Type: issue Value: 5 Titles: – TitleFull: Applied Sciences (2076-3417) Type: main |
| ResultId | 1 |