FlowWatcher: Defending against data disclosure vulnerabilities in web applications
Dan O'Keeffe, Imperial College London
Bugs in the authorisation logic of web applications can expose the data of one user to another. Such data disclosure vulnerabilities are common—they can be caused by a single omitted access control check in the application. However, while the implementation of the authorisation logic is complex and therefore error-prone, most web applications only use simple access control models, in which each piece of data is accessible by a user or a group of users. This makes it possible to validate the correct operation of the authorisation logic externally, based on the observed data in HTTP traffic to and from an application. In this talk I will describe FlowWatcher, an HTTP proxy that mitigates data disclosure vulnerabilities in unmodified web applications. FlowWatcher monitors HTTP traffic and shadows part of an application’s access control state based on a rule-based specification of the user-data-access (UDA) policy. The UDA policy states the intended data ownership and how it changes based on observed HTTP requests. FlowWatcher detects violations of the UDA policy by tracking data items that are likely to be unique across HTTP requests and responses of different users. Our evaluation of a prototype implementation of FlowWatcher as a plug-in for the Nginx reverse proxy shows that, with short UDA policies, it can mitigate CVE bugs in six popular web applications. FlowWatcher has been accepted for publication at CCS '15, for which this is a practice talk.
Date & Time
Thursday, October 8, 2015 - 14:00