arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ReDoS漏洞与ReDoS检测工具的实证分析

An Empirical Analysis of ReDoS Vulnerabilities and ReDoS Detection Tools

N'Zolieh Ismaël Mahassadi, Raphaël Khoury, Justin Vallé, Abdelwahab Hamou-Lhadj

arXiv 2609.10294首次发表:更新:

发表机构

Université du Québec en Outaouais; Concordia Universiy(魁北克大学欧塔瓦校区; 康考迪亚大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究实证分析ReDoS漏洞及检测工具,发现此类漏洞日益普遍且更易被利用,且现有检测工具对漏洞判定存在显著分歧。

AI 中文摘要

ReDoS漏洞是一种拒绝服务软件弱点,当使用正则表达式验证用户提供的输入时会发生。在某些情况下,正则表达式匹配过程可能花费指数时间,导致拒绝服务。在本研究中,我们使用三个数据集,检验并比较了五种公开可用的正则表达式检测工具和一种正则表达式修正工具的有效性。我们进一步对报告给NVD数据库的所有ReDoS漏洞进行了实证分析,以了解它们与非ReDoS漏洞的差异,并获取关于此类弱点的见解。我们发现,ReDoS漏洞正变得越来越普遍,并且比非ReDoS漏洞更有可能被利用。我们还发现,检测工具在给定正则表达式是否易受攻击方面表现出实质性分歧。

英文摘要

ReDoS vulnerabilities are a type of denial of service software weakness that occurs when a regex is used to validate user-supplied input. In some cases, the regex matching process can take exponential time, leading to a denial of service. In this study, we examine and compare the effectiveness of five publicly-available regex detection tools, and one regex correction tool, using three datasets. We further perform an empirical analysis of all ReDoS vulnerabilities reported to the NVD database in order to understand how they differ from non-ReDoS vulnerabilities and glean insights about this type of weakness. We find that ReDoS vulnerabilities are becoming more prevalent and are much more likely to be exploited than non-ReDoS vulnerabilities. We further find that detection tools exhibit substantial disagreement on whether or not a given regex is vulnerable.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑