发表机构
School of Computer Science and Artificial Intelligence, Zhengzhou University; School of Computer Science, Fudan University; Institute of Big Data, Fudan University; School of Cyber Science and Engineering, Zhengzhou University(郑州大学计算机科学与人工智能学院; 复旦大学计算机科学与技术学院; 复旦大学大数据研究院; 郑州大学网络空间安全学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
IDORacle通过模板引导的SQL汇点拦截与重写,在Java应用中运行时防止水平权限提升,利用身份传播和双重指纹分析生成调解计划,实现低延迟防护。
AI 中文摘要
不安全的直接对象引用(IDOR),通常被建模为破坏的对象级授权(BOLA),在Java数据库应用中仍然普遍存在,因为控制器或服务层的身份和授权检查与基于资源标识符的SQL执行相脱节。现有工作主要检测这些漏洞,但对遗留Java-SQL应用提供的低侵入性运行时保护有限。我们提出了IDORacle,一个模板引导的SQL汇点拦截与重写框架,用于在运行时防止水平权限提升。IDORacle通过服务器端跟踪标识符,在HTTP请求、异步任务和数据访问边界之间传播经过认证的身份上下文。在MyBatis/JDBC边界,它提取SQL模板,计算双重指纹,并执行一次性模板分析以生成可复用的调解计划。在执行期间,它结合主体上下文、SQL抽象语法树(AST)、表元数据和缓存的授权证明来允许、重写或阻止操作。其防护模型支持直接所有权谓词、连接衍生的所有权、对组拥有资源的探测、角色敏感的状态转换以及敏感列调解。一个基于真实CVE报告的Java-SQL基准测试表明,IDORacle能够阻止测试的水平授权违规,最坏情况下的防护延迟为0.17毫秒。冗余感知优化将平均每实例开销降低超过90%,对于热SQL模板降至0.017毫秒。
英文摘要
Insecure Direct Object Reference (IDOR), often modeled as Broken Object-Level Authorization (BOLA), remains prevalent in Java database applications because identity and authorization checks at the controller or service layer are disconnected from SQL execution based on resource identifiers. Existing work largely detects these vulnerabilities but offers limited low-intrusion runtime protection for legacy Java-SQL applications. We present IDORacle, a template-guided SQL-sink interception and rewriting framework for preventing horizontal privilege escalation at runtime. IDORacle propagates authenticated identity context across HTTP requests, asynchronous tasks, and data-access boundaries through a server-side trace identifier. At the MyBatis/JDBC boundary, it extracts SQL templates, computes dual fingerprints, and performs one-time template analysis to generate reusable mediation plans. During execution, it combines subject context, SQL ASTs, table metadata, and cached authorization proofs to permit, rewrite, or block operations. Its guard model supports direct ownership predicates, join-derived ownership, probes for group-owned resources, role-sensitive state transitions, and sensitive-column mediation. A Java-SQL benchmark grounded in real-world CVE reports shows that IDORacle prevents the tested horizontal authorization violations with a worst-case guard latency of 0.17 ms. Redundancy-aware optimization reduces average per-instance overhead by more than 90%, to 0.017 ms for hot SQL templates.
Comments16 pages, 3 figures. This manuscript reflects the pre-peer-review version of the work. A peer-reviewed journal version, titled "IDORacle: Template-Guided Data-Access Mediation for Object-Level Authorization in Database-Backed Applications," is available online in Computers & Security: https://doi.org/10.1016/j.cose.2026.105143
DOI:10.1016/j.cose.2026.105143