通过构造中间查询结果的等价表示来检测数据库管理系统(DBMS)漏洞
Detecting DBMS Bugs by Constructing Equivalent Representations of Intermediate Query Results
浏览论文内容
中文总结 AI 辅助
该研究提出ERIQ方法,通过对比VIEW、CTE、TEMPT表示相同中间查询结果的SQL变体的结果一致性,在4款开源DBMS中检测到64个漏洞,其中54个为未知逻辑漏洞。
中文摘要 AI 辅助
数据库管理系统(DBMS)支持多种用于表示中间查询结果的SQL机制,包括视图(VIEW)、通用表表达式(CTE)和临时表(TEMPT)。当使用这些机制表示相同的中间查询结果时,相应的查询应产生一致的结果。然而,我们观察到这类查询可能返回不一致的结果,这表明存在潜在的DBMS逻辑漏洞。现有的检测DBMS逻辑漏洞的方法从未探索过这类等价表示之间的结果一致性。在本文中,我们提出ERIQ,一种新颖的测试方法,用于从检查中间查询结果的等价表示之间的结果一致性的角度检测DBMS逻辑漏洞。ERIQ使用VIEW、CTE或TEMPT构造SQL变体以表示相同的中间查询结果,执行这些变体并比较它们的返回结果。我们在四种广泛使用的开源DBMS(MySQL、MariaDB、Percona和OceanBase)上评估了ERIQ。总体而言,ERIQ检测到64个漏洞,其中63个已被开发者确认,2个已被修复。在已确认的漏洞中,54个是独特且此前未知的逻辑漏洞,1个是文档问题。
英文摘要
Database Management Systems (DBMSs) support multiple SQL mechanisms for representing intermediate query results, including VIEWs, Common Table Expressions (CTEs), and Temporary Tables (TEMPTs). When these mechanisms are used to represent the same intermediate query result, the corresponding queries are expected to produce consistent results. However, we observe that such queries can return inconsistent results, indicating potential DBMS logic bugs. Existing approaches for detecting DBMS logic bugs have never explored result consistency across such equivalent representations. In this paper, we propose ERIQ, a novel testing approach for detecting DBMS logic bugs from the perspective of checking result consistency across Equivalent Representations of Intermediate Query Results. ERIQ constructs SQL variants using a VIEW, a CTE, or a TEMPT to represent the same intermediate query result, executes these variants, and compares their returned results. We evaluated ERIQ on four widely used open-source DBMSs: MySQL, MariaDB, Percona, and OceanBase. In total, ERIQ detected 64 bugs, 63 of which were confirmed by developers, and two have been fixed. Among the confirmed bugs, 54 were unique and previously unknown logic bugs, and one was a documentation issue.
发表机构
- Wuhan University(武汉大学)
机构由 AI 辅助整理,请以论文原文为准。