Comprehensive Java Metadata Tracking for Attack Detection and Repair
© 2020 IEEE. We present ClearTrack, a system that tracks meta-data for each primitive value in Java programs to detect and nullify a range of vulnerabilities such as integer overflow/underflow and SQL/command injection vulnerabilities. Contributions include new techniques for eliminating false posit...
Main Authors: | , , , |
---|---|
Other Authors: | |
Format: | Article |
Language: | English |
Published: |
IEEE
2021
|
Online Access: | https://hdl.handle.net/1721.1/137581 |
_version_ | 1811072724051689472 |
---|---|
author | Perkins, Jeff Eikenberry, Jordan Coglio, Allessandro Rinard, Martin |
author2 | Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory |
author_facet | Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory Perkins, Jeff Eikenberry, Jordan Coglio, Allessandro Rinard, Martin |
author_sort | Perkins, Jeff |
collection | MIT |
description | © 2020 IEEE. We present ClearTrack, a system that tracks meta-data for each primitive value in Java programs to detect and nullify a range of vulnerabilities such as integer overflow/underflow and SQL/command injection vulnerabilities. Contributions include new techniques for eliminating false positives associated with benign integer overflows and underflows, new metadata-aware techniques for detecting and nullifying SQL/command command injection attacks, and results from an independent evaluation team. These results show that 1) ClearTrack operates successfully on Java programs comprising hundreds of thousands of lines of code (including instrumented jar files and Java system libraries, the majority of the applications comprise over 3 million lines of code), 2) because of computations such as cryptography and hash table calculations, these applications perform millions of benign integer overflows and underflows, and 3) ClearTrack successfully detects and nullifies all tested integer overflow and underflow and SQL/command injection vulnerabilities in the benchmark applications. |
first_indexed | 2024-09-23T09:11:01Z |
format | Article |
id | mit-1721.1/137581 |
institution | Massachusetts Institute of Technology |
language | English |
last_indexed | 2024-09-23T09:11:01Z |
publishDate | 2021 |
publisher | IEEE |
record_format | dspace |
spelling | mit-1721.1/1375812022-09-26T10:59:08Z Comprehensive Java Metadata Tracking for Attack Detection and Repair Perkins, Jeff Eikenberry, Jordan Coglio, Allessandro Rinard, Martin Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory © 2020 IEEE. We present ClearTrack, a system that tracks meta-data for each primitive value in Java programs to detect and nullify a range of vulnerabilities such as integer overflow/underflow and SQL/command injection vulnerabilities. Contributions include new techniques for eliminating false positives associated with benign integer overflows and underflows, new metadata-aware techniques for detecting and nullifying SQL/command command injection attacks, and results from an independent evaluation team. These results show that 1) ClearTrack operates successfully on Java programs comprising hundreds of thousands of lines of code (including instrumented jar files and Java system libraries, the majority of the applications comprise over 3 million lines of code), 2) because of computations such as cryptography and hash table calculations, these applications perform millions of benign integer overflows and underflows, and 3) ClearTrack successfully detects and nullifies all tested integer overflow and underflow and SQL/command injection vulnerabilities in the benchmark applications. 2021-11-05T18:57:22Z 2021-11-05T18:57:22Z 2020-06 2021-03-10T14:35:49Z Article http://purl.org/eprint/type/ConferencePaper https://hdl.handle.net/1721.1/137581 Perkins, Jeff, Eikenberry, Jordan, Coglio, Allessandro and Rinard, Martin. 2020. "Comprehensive Java Metadata Tracking for Attack Detection and Repair." Proceedings - 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2020. en 10.1109/dsn48063.2020.00024 Proceedings - 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2020 Creative Commons Attribution-Noncommercial-Share Alike http://creativecommons.org/licenses/by-nc-sa/4.0/ application/pdf IEEE MIT web domain |
spellingShingle | Perkins, Jeff Eikenberry, Jordan Coglio, Allessandro Rinard, Martin Comprehensive Java Metadata Tracking for Attack Detection and Repair |
title | Comprehensive Java Metadata Tracking for Attack Detection and Repair |
title_full | Comprehensive Java Metadata Tracking for Attack Detection and Repair |
title_fullStr | Comprehensive Java Metadata Tracking for Attack Detection and Repair |
title_full_unstemmed | Comprehensive Java Metadata Tracking for Attack Detection and Repair |
title_short | Comprehensive Java Metadata Tracking for Attack Detection and Repair |
title_sort | comprehensive java metadata tracking for attack detection and repair |
url | https://hdl.handle.net/1721.1/137581 |
work_keys_str_mv | AT perkinsjeff comprehensivejavametadatatrackingforattackdetectionandrepair AT eikenberryjordan comprehensivejavametadatatrackingforattackdetectionandrepair AT coglioallessandro comprehensivejavametadatatrackingforattackdetectionandrepair AT rinardmartin comprehensivejavametadatatrackingforattackdetectionandrepair |