kirancodes.me
To Proof Maintenance & Beyond!

Exploiting Input Sanitization for Regex Denial of Service

Efe Barlas, Xin Du, James C. Davis

Abstract

Web services use server-side input sanitization to guard against harmful input. Some web services publish their sanitization logic to make their client interface more usable, e.g., allowing clients to debug invalid requests locally. However, this usability practice poses a security risk. Specifically, services may share the regexes they use to sanitize input strings --- and regex-based denial of service (ReDoS) is an emerging threat. Although prominent service outages caused by ReDoS have spurred interest in this topic, we know little about the degree to which live web services are vulnerable to ReDoS.

BibTeX
@inproceedings{Barlas-al:ICSE22,
  author    = {Efe Barlas and
               Xin Du and
               James C. Davis},
  title     = {Exploiting Input Sanitization for Regex Denial of Service},
  booktitle = {ICSE},
  pages     = {883--895},
  publisher = {{ACM}},
  year      = {2022},
}

Related papers