Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
    • Advisor
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 電機資訊學院
  3. 資訊網路與多媒體研究所
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/84947
Title: 在 Node.js 函式庫中動態偵測原型鏈污染漏洞
Dynamic Detection of Prototype Pollution Vulnerability in Node.js Library
Authors: Yuan-Chun Chu
朱元均
Advisor: 吳家麟(Ja-Ling Wu)
Keyword: Node.js,原型鏈污染,模糊測試,
Node.js,PrototypePollution,Fuzzing,
Publication Year : 2022
Degree: 碩士
Abstract: 本論文提出了一套框架能夠自動地在 Node.js 的函式庫中偵測原型鏈污染漏洞,並自動產生相對應的漏洞利用以驗證漏洞的存在。此框架包含了可以分開獨立實作與優化的六個步驟,依序從尋找目標、分割程式碼、植入程式碼、模糊測試、產生漏洞利用到驗證漏洞利用,結合靜態分析與動態分析的優勢,並分析利 用原型鏈污染漏洞的特性,盡可能地找出所有原型鏈污染漏洞。最後,依照每一步驟的定義,本論文實作了一套概念性驗證的工具,來驗證並分析此架構的可行性與效能。
This thesis proposes a framework that automatically detects Prototype Pollution Vul- nerabilities in the Node.js library and automatically generates the corresponding exploits to verify the existence of vulnerabilities. The proposed framework comprises six phases that can be implemented and optimized independently. The six phases include: finding targets, segmenting code, injecting code, fuzzing, generating exploits, and verifying ex- ploits, which combines the advantages of static and dynamic analysis and makes analyzing the concept of Prototype Pollution to find all vulnerabilities as much as possible. By ade- quately defining each phase, we implemented proof-of-concept tools to verify and analyze the feasibility and effectiveness of the framework.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/84947
DOI: 10.6342/NTU202201333
Fulltext Rights: 同意授權(限校園內公開)
metadata.dc.date.embargo-lift: 2022-08-24
Appears in Collections:資訊網路與多媒體研究所

Files in This Item:
File SizeFormat 
U0001-0707202216093800.pdf
Access limited in NTU ip range
3.63 MBAdobe PDF
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved