arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ABSENTIA:检测Web应用程序中失效的访问控制漏洞

ABSENTIA: Detecting Broken Access Control Vulnerabilities in Web Applications

André V. Duarte, Aditya Oke, Rui Melo, Shubham Gandhi, Nachiket Kotalwar, Charmi Khandor, Danqing Wang, Arlindo L. Oliveira, Carolyn Rosé, Lei Li

arXiv 2610.00977首次发表:更新:

发表机构

Carnegie Mellon University; Instituto Superior Técnico; Faculdade de Engenharia do Porto(卡内基梅隆大学; 技术高等研究所; 波尔图工程学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对Web应用失效的访问控制漏洞,提出安全脚手架ABSENTIA,引导LLM智能体通过路由映射和不变式反驳实现系统性检测,并发布BAC-Bench基准,召回19/30漏洞,优于现有工具。

AI 中文摘要

失效的访问控制,即授权失败,是最普遍的Web安全风险之一。与注入(将不可信输入流入危险操作)不同,授权是一种关系:谁可以对什么采取行动,而不是数据如何流动。每个应用程序都自行决定这种关系,因此预先编写的规则无法适用于下一个应用程序。LLM智能体可以从代码中推断出这种关系,但由于缺乏系统性的方法来覆盖应用程序并确定检查的优先级,其搜索仍然缺乏方向性,访问控制缺陷因而未被发现。我们提出了ABSENTIA,一种安全脚手架,它将通用LLM智能体转变为针对Web应用程序后端的系统性漏洞检测器,由维护代码的开发人员和安全工程师作为审计运行。在其指导下,智能体构建了一个将应用程序路由映射到其背后代码的图。ABSENTIA随后逐路由地应用不变式反驳:它推断代码旨在满足的属性,并在某个属性未被强制执行时,报告该路由以供维护人员审查。我们还发布了BAC-Bench,一个包含30条失效访问控制公告的基准,涵盖25个存储库、3种语言和9个框架,每条公告均于2025年或之后发布,经人工审计员验证,并配有相应的修复提交,因此获得认可需要标记易受攻击的版本而非已修复的版本。ABSENTIA召回了其中19条,其中17条在配对认可下,且一个LLM验证器确认了其51%的发现。CodeQL和Semgrep的召回率为零,而同一模型上的非结构化智能体召回了3条。在OWASP基准注入类别中,ABSENTIA在Python方面领先于专用分析器,在Java方面仅落后于CodeQL和IRIS。

英文摘要

Broken access control, the failure of authorization, is one of the most prevalent web security risks. Unlike injection, a flow of untrusted input into a dangerous operation, authorization is a relation: who may act on what, not how data moves. Each application decides that relation for itself, so no rule written in advance carries to the next. An LLM agent can infer it from the code, but with no systematic way to cover the application and prioritize what to inspect, its search stays undirected and access-control flaws go undetected. We present ABSENTIA, a security scaffolding that turns general LLM agents into systematic vulnerability detectors for the backend of web applications, run as an audit by the developers and security engineers who maintain the code. Under its direction, the agents build a graph that maps the application's routes to the code behind them. ABSENTIA then works route by route, applying invariant falsification: it infers the properties the code is meant to satisfy, and where one is not enforced, reports the route for maintainer review. We also release BAC-Bench, a benchmark of 30 broken access control advisories across 25 repositories, 3 languages, and 9 frameworks, each published in 2025 or later, verified by a human auditor, and paired with its fixing commit, so credit requires flagging the vulnerable version and not the fixed one. ABSENTIA recalls 19 of them, 17 under paired credit, and an LLM verifier confirms 51% of its findings. CodeQL and Semgrep recall none, and an unstructured agent on the same model recalls 3. In the OWASP Benchmark injection categories, ABSENTIA leads the dedicated analyzers in Python and trails only CodeQL and IRIS in Java.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑