kirancodes.me
To Proof Maintenance & Beyond!

Compile-Time Detection of Machine Image Sniping

Martin Kellogg

Abstract

Machine image sniping is a difficult-to-detect security vulnerability in cloud computing code. When programmatically initializing a machine, a developer specifies a machine image (operating system and file system). The developer should restrict the search to only those machine images which their organization controls: otherwise, an attacker can insert a similarly-named malicious image into the public database, where it might be selected instead of the image the developer intended. We present a lightweight type and effect system that detects requests to a cloud provider that are vulnerable to an image sniping attack, or proves that no vulnerable request exists in a codebase. We prototyped our type system for Java programs that initialize Amazon Web Services machines, and evaluated it on more than 500 codebases, detecting 14 vulnerable requests with only 3 false positives.

BibTeX
@inproceedings{Kellogg:ASE19,
  author    = {Martin Kellogg},
  title     = {{Compile-Time} Detection of Machine Image Sniping},
  booktitle = {ASE},
  pages     = {1256--1258},
  publisher = {{IEEE}},
  year      = {2019},
}

Related papers