Bi-directional Taint Flow Analysis: A High-precision Static Detection Approach for Java Deserialization Vulnerabilities
Haihua Liu, Yanrong Lu
Civil Aviation University of China
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
The Java deserialization vulnerability represents a significant security threat to enterprise applications, enabling attackers to execute malicious code through crafted serialized data. Current detection approaches struggle with accurately identifying complex exploit chains and effectively capturing comprehensive data flow paths through traditional one-way taint analysis, resulting in false positives and missed vulnerabilities. Our proposed bi-directional taint flow analysis method innovatively combines forward taint propagation with reverse sensitivity analysis to precisely identify potential deserialization exploit chains through intersection analysis. Experimental results demonstrate that our SerialVulnScanner implementation achieves a 74.3% detection rate on mainstream Java components—6.9 percentage points higher than existing tools—with particular effectiveness in handling complex code structures and atypical exploit chains, thereby providing enhanced security for Java applications.
逐年被引趋势
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AISoftware Reliability and Analysis Research
Advanced Malware Detection Techniques · Security and Verification in Computing
参考文献 8
此处列出前 3 条
引用本文 1
按被引量排序,此处列出前 3 条