Proceedings 2024 Network and Distributed System Security Symposium 2024
DOI: 10.14722/ndss.2024.241015
|View full text |Cite
|
Sign up to set email alerts
|

QUACK: Hindering Deserialization Attacks via Static Duck Typing

Yaniv David,
Neophytos Christou,
Andreas D. Kellas
et al.

Abstract: Managed languages facilitate convenient ways for serializing objects, allowing applications to persist and transfer them easily, yet this feature opens them up to attacks. By manipulating serialized objects, attackers can trigger a chained execution of existing code segments, using them as gadgets to form an exploit. Protecting deserialization calls against attacks is cumbersome and tedious, leading to many developers avoiding deploying defenses properly. We present QUACK, a framework for automatically protect… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...

Citation Types

0
0
0

Year Published

2024
2024
2024
2024

Publication Types

Select...
1

Relationship

0
1

Authors

Journals

citations
Cited by 1 publication
references
References 23 publications
(28 reference statements)
0
0
0
Order By: Relevance