Bài viết

Tấn công biểu thức chính quy dựa trên lỗ hổng ReDoS

Từ khóabiểu thức chính quykỹ thuật fuzzingautomatonambiguitylỗ hổng ReDoS

Tóm tắt

Tóm tắt— Biểu thức chính quy (regex) là một phần không thể thiếu trong phát triển ứng dụng phần mềm, được tích hợp một cách liền mạch vào vô số ứng dụng. Biểu thức chính quy được sử dụng trong nhiều nhiệm vụ khác nhau từ xác thực đầu vào của người dùng ứng dụng web đến phân tích dữ liệu văn bản phức tạp. Tuy nhiên, sự phụ thuộc vào biểu thức chính quy cũng mang đến một lỗ hổng bảo mật nghiêm trọng như tấn công ReDoS (Regular Expression Denial of Service - Tấn công từ chối dịch vụ trên biểu thức chính quy). Tấn công ReDoS khai thác dựa trên sự phức tạp của việc so khớp biểu thức chính quy bằng cách tạo ra đầu vào độc hại để thời gian xử lý tăng theo cấp số mũ, khiến ứng dụng ngừng hoạt động. Mục đích của các cuộc tấn công ReDoS tập trung vào các nhà phát triển phần mềm khi thiết kế và triển khai các thành phần dựa trên biểu thức chính quy trong sản phẩm. Bài báo bao gồm thuật toán ambiguity của biểu thức chính quy, kỹ thuật fuzzing kết hợp với phân tích tĩnh, từ đó đề xuất một kỹ thuật mới để tạo ra các mẫu tấn công hiệu quả. Bằng cách phân tích cấu trúc ambiguity, nhóm tác giả đã xác định phương pháp và kỹ thuật khai thác điểm yếu trong cách triển khai phần mềm dựa vào biểu thức chính quy để xác thực đầu vào. Thuật toán đề xuất được thực nghiệm một cách có hệ thống, tối ưu hóa khả năng phát hiện các lỗ hổng liên quan đến hành vi trên biểu thức chính quy. Cách tiếp cận của bài báo nhằm tăng cường bảo mật phần mềm thông qua việc chủ động phát hiện và giảm thiểu các vectơ tấn công tiềm ẩn phát sinh từ việc hiểu sai cách sử dụng biểu thức chính quy.

Lượt tải theo tháng

091806/2407/2408/2409/2410/2411/2412/2402/2503/2504/2505/2506/2507/2508/2509/2510/2511/2512/2501/2602/2603/2604/26

Di chuột vào cột để xem số lượt tải.

Cách trích dẫn

Nguyễn Trung Dũng, Phạm Văn Tới, Phùng Minh Hiếu (2024). Tấn công biểu thức chính quy dựa trên lỗ hổng ReDoS. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 1(21), 5-15. https://doi.org/10.54654/isj.v1i21.1030

Tài liệu tham khảo

  1. 1.OWASP (2010-02-10). "Regex Denial of Service". Retrieved 2010-04-16.
  2. 2.Son, D. T., Tram, N. T. K., & Thu, T. T. . (2022). Machine learning approach detects DDoS attacks. Journal of Science and Technology on Information Security, 1(15), 102-108. https://doi.org/10.54654/isj.v1i15.850.
  3. 3.Martin Berglund, Frank Drewes, Brink van der Merwe. 2014. Analyzing Catastrophic Backtracking Behavior in Practical Regular Expression Matching. Electronic Proceedings in Theoretical Computer Science 151(Proc. AFL 2014).
  4. 4.Efe Barla, Xin Du, James C. Davis. 2023. Exploiting Input Sanitization for Regex Denial of Service. Proceedings of the ACM/IEEE 44th International Conference on Software Engineering (ICSE) 2022. https://arxiv.org/abs/2303.01996.
  5. 5."Backtracking in .NET regular expressions - .NET". learn.microsoft.com. 11 August 2023. When using System.Text.RegularExpressions to process untrusted input, pass a timeout. A malicious user can provide input to RegularExpressions, causing a Denial-of-Service attack. ASP.NET Core framework APIs that use RegularExpressions pass a timeout.
  6. 6.Li, Yeting, et al. "ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS Detection." 30th USENIX Security Symposium (USENIX Security 21). 2021.
  7. 7.Davis, James C., Francisco Servant, and Dongyoon Lee. 2021. "Using selective memoization to defeat regular expression denial of service (ReDoS)." 2021 IEEE Symposium on Security and Privacy (SP), Los Alamitos, CA, USA.
  8. 8.Paul Wilton. Beginning JavaScript. John Wiley & Sons, 2004.
  9. 9.Pieter Hooimeijer, Benjamin Livshits, David Molnar, Prateek Saxena, and Margus Veanes. Fast and precise sanitizer analysis with BEK. In USENIX Security Symposium, pages 1–16, August 2011.
  10. 10.https://en.wikipedia.org/wiki/Thompson's_construction.
  11. 11.Sugiyama, Satoshi, and Yasuhiko Minamide. "Checking time linearity of regular expression matching based on backtracking." Information and Media Technologies 9.3 (2014): 222-232.
  12. 12.Shen, Yuju, et al. "ReScue: crafting regular expression DoS attacks." 2018 33rd IEEE/ACM International Conference on Automated Software Engineering (ASE). IEEE, 2018.
  13. 13.Chida, Nariyoshi, and Tachio Terauchi. 2020."Automatic repair of vulnerable regular expressions." arXiv preprint arXiv:2010.12450.
  14. 14.Theofilos Petsios, Jason Zhao, Angelos D Keromytis, and Suman Jana. 2017. Slowfuzz: Automated domain-independent detection of algorithmic complexity vulnerabilities. In Proceedings of the International Conference on Computer and Communications Security (CCS ’17). 2155–2168. https://doi.org/10.1145/3133956. 3134073.
  15. 15.James Kirrage, Asiri Rathnayake, and Hayo Thielecke. 2013. Static analysis for regular expression denial-of-service attacks. In Proceedings of the 7th International Conference on Network and System Security (NSS ’13). 135–148. https://doi.org/ 10.1007/978-3-642-38631-2_11.
  16. 16.Valentin Wüstholz, Oswaldo Olivo, Marijn JH Heule, and Isil Dillig. 2017. Static detection of DoS vulnerabilities in programs that use regular expressions. In Proceedings of the International Conference on Tools and Algorithms for the Construction and Analysis of Systems (TACAS ’17). 3–20. https://doi.org/10.1007/ 978-3-662-54580-5_1.
  17. 17.Nicolaas Weideman, Brink van der Merwe, Martin Berglund, and Bruce Watson. 2016. Analyzing matching time behavior of backtracking regular expression matchers by using ambiguity of NFA. In Proceedings of the International Conference on Implementation and Application of Automata (CIAA ’16). 322–334. https: //doi.org/10.1007/978-3-319-40946-7_27.
  18. 18.Weber, Andreas, and Helmut Seidl. 1991. "On the degree of ambiguity of finite automata." Theoretical Computer Science 88.2 (1991): 325-349.
  19. 19.Asiri Rathnayake and Hayo Thielecke. 2014. Static analysis for regular expression exponential runtime via substructural logics. (2014). arXiv:arXiv:1405.7058.
  20. 20.Carl Chapman and Kathryn T Stolee. 2016. Exploring regular expression usage and context in Python. In Proceedings of the 25th International Symposium on Software Testing and Analysis (ISSTA ’16). 282–293. https://doi.org/10.1145/ 2931037.2931073.

Bài viết liên quan