Academic Journal

Analyzing and Discovering Spatial Algorithm Complexity Vulnerabilities in Recursion.

Bibliographic Details
Title: Analyzing and Discovering Spatial Algorithm Complexity Vulnerabilities in Recursion.
Authors: Wang, Ziqi, Bu, Debao, Tian, Weihan, Cui, Baojiang
Source: Applied Sciences (2076-3417); Mar2024, Vol. 14 Issue 5, p1855, 19p
Subject Terms: Denial of service attacks, Algorithms
Abstract: The algorithmic complexity vulnerability (ACV) that may lead to denial of service attacks greatly disrupts the security and availability of applications, and due to the widespread use of third-party libraries, its impact may be amplified through the software supply chain. The existing work in the field is dedicated to abstract loop or iterative patterns and fuzzing the entire application to discover algorithm complexity vulnerabilities, but they still face efficiency and effectiveness issues. Our research focuses on: (1) proposing a representation and extraction method for code features related to algorithmic complexity vulnerabilities, helping analysts quickly understand program logic; (2) providing a new ACV detecting model, focusing on the spatial complexity anomalies caused by deep recursion structures, and proposing a new filtering method; and (3) aiming at the difficulty of efficiently generating complex-data-type-related payloads using existing symbol execution techniques, a call-chain-guided payload construction method is proposed. We tested third-party components in the open-source Java Maven Repository, identified many unexposed vulnerabilities, and eight of them received Common Vulnerabilities and Exposures (CVE) identifiers, and demonstrated that our method can discover more algorithmic complexity vulnerabilities compared to existing tools with better performance. [ABSTRACT FROM AUTHOR]
Copyright of Applied Sciences (2076-3417) is the property of MDPI and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Complementary Index
FullText Text:
  Availability: 0
CustomLinks:
  – Url: https://resolver.ebsco.com/c/fiv2js/result?sid=EBSCO:edb&genre=article&issn=20763417&ISBN=&volume=14&issue=5&date=20240301&spage=1855&pages=1855-1873&title=Applied Sciences (2076-3417)&atitle=Analyzing%20and%20Discovering%20Spatial%20Algorithm%20Complexity%20Vulnerabilities%20in%20Recursion.&aulast=Wang%2C%20Ziqi&id=DOI:10.3390/app14051855
    Name: Full Text Finder (for New FTF UI) (ns324271)
    Category: fullText
    Text: Full Text Finder
    MouseOverText: Full Text Finder
Header DbId: edb
DbLabel: Complementary Index
An: 175987908
RelevancyScore: 958
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 957.825012207031
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Analyzing and Discovering Spatial Algorithm Complexity Vulnerabilities in Recursion.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Wang%2C+Ziqi%22">Wang, Ziqi</searchLink><br /><searchLink fieldCode="AR" term="%22Bu%2C+Debao%22">Bu, Debao</searchLink><br /><searchLink fieldCode="AR" term="%22Tian%2C+Weihan%22">Tian, Weihan</searchLink><br /><searchLink fieldCode="AR" term="%22Cui%2C+Baojiang%22">Cui, Baojiang</searchLink>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: Applied Sciences (2076-3417); Mar2024, Vol. 14 Issue 5, p1855, 19p
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Denial+of+service+attacks%22">Denial of service attacks</searchLink><br /><searchLink fieldCode="DE" term="%22Algorithms%22">Algorithms</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: The algorithmic complexity vulnerability (ACV) that may lead to denial of service attacks greatly disrupts the security and availability of applications, and due to the widespread use of third-party libraries, its impact may be amplified through the software supply chain. The existing work in the field is dedicated to abstract loop or iterative patterns and fuzzing the entire application to discover algorithm complexity vulnerabilities, but they still face efficiency and effectiveness issues. Our research focuses on: (1) proposing a representation and extraction method for code features related to algorithmic complexity vulnerabilities, helping analysts quickly understand program logic; (2) providing a new ACV detecting model, focusing on the spatial complexity anomalies caused by deep recursion structures, and proposing a new filtering method; and (3) aiming at the difficulty of efficiently generating complex-data-type-related payloads using existing symbol execution techniques, a call-chain-guided payload construction method is proposed. We tested third-party components in the open-source Java Maven Repository, identified many unexposed vulnerabilities, and eight of them received Common Vulnerabilities and Exposures (CVE) identifiers, and demonstrated that our method can discover more algorithmic complexity vulnerabilities compared to existing tools with better performance. [ABSTRACT FROM AUTHOR]
– Name: Abstract
  Label:
  Group: Ab
  Data: <i>Copyright of Applied Sciences (2076-3417) is the property of MDPI and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edb&AN=175987908
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.3390/app14051855
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 19
        StartPage: 1855
    Subjects:
      – SubjectFull: Denial of service attacks
        Type: general
      – SubjectFull: Algorithms
        Type: general
    Titles:
      – TitleFull: Analyzing and Discovering Spatial Algorithm Complexity Vulnerabilities in Recursion.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Wang, Ziqi
      – PersonEntity:
          Name:
            NameFull: Bu, Debao
      – PersonEntity:
          Name:
            NameFull: Tian, Weihan
      – PersonEntity:
          Name:
            NameFull: Cui, Baojiang
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 03
              Text: Mar2024
              Type: published
              Y: 2024
          Identifiers:
            – Type: issn-print
              Value: 20763417
          Numbering:
            – Type: volume
              Value: 14
            – Type: issue
              Value: 5
          Titles:
            – TitleFull: Applied Sciences (2076-3417)
              Type: main
ResultId 1