April 11, 2023, 1:10 a.m. | Sicong Cao, Biao He, Xiaobing Sun, Yu Ouyang, Chao Zhang, Xiaoxue Wu, Ting Su, Lili Bo, Bin Li, Chuanlei Ma, Jiajia Li, Tao Wei

cs.CR updates on arXiv.org arxiv.org

Java deserialization vulnerability is a severe threat in practice.
Researchers have proposed static analysis solutions to locate candidate
vulnerabilities and fuzzing solutions to generate proof-of-concept (PoC)
serialized objects to trigger them. However, existing solutions have limited
effectiveness and efficiency. In this paper, we propose a novel hybrid solution
ODDFUZZ to efficiently discover Java deserialization vulnerabilities. First,
ODDFUZZ performs lightweight static taint analysis to identify candidate gadget
chains that may cause deserialization vulner-abilities. In this step, ODDFUZZ
tries to locate all …

analysis aware concept deserialization discover efficiency false negatives fuzzing gadget hybrid identify java java deserialization may novel poc practice proof-of-concept researchers solution solutions static analysis taint analysis threat trigger vulnerabilities vulnerability

Lead Security Specialist

@ Fujifilm | Holly Springs, NC, United States

Security Operations Centre Analyst

@ Deliveroo | Hyderabad, India (Main Office)

CISOC Analyst

@ KCB Group | Kenya

Lead Security Engineer – Red Team/Offensive Security

@ FICO | Work from Home, United States

Cloud Security SME

@ Maveris | Washington, District of Columbia, United States - Remote

SOC Analyst (m/w/d)

@ Bausparkasse Schwäbisch Hall | Schwäbisch Hall, DE