Preprint Open Access

[Preprint] ObjectMap: Detecting Insecure Object Deserialization

Koutroumpouchos Nikolaos; Lavdanis Georgios; Veroni Eleni; Ntantogian Christoforos; Xenakis Christos


JSON Export

{
  "files": [
    {
      "links": {
        "self": "https://zenodo.org/api/files/3bcdb590-4aa4-4af3-baed-24b1382d32f9/25-ObjectMap%20Detecting%20Insecure%20Object%20Deserialization.pdf"
      }, 
      "checksum": "md5:dc5dae19513ae373eed7355fdfaed0c3", 
      "bucket": "3bcdb590-4aa4-4af3-baed-24b1382d32f9", 
      "key": "25-ObjectMap Detecting Insecure Object Deserialization.pdf", 
      "type": "pdf", 
      "size": 515635
    }
  ], 
  "owners": [
    64513
  ], 
  "doi": "10.5281/zenodo.3553676", 
  "stats": {
    "version_unique_downloads": 1391.0, 
    "unique_views": 58.0, 
    "views": 69.0, 
    "version_views": 69.0, 
    "unique_downloads": 1391.0, 
    "version_unique_views": 58.0, 
    "volume": 754374005.0, 
    "version_downloads": 1463.0, 
    "downloads": 1463.0, 
    "version_volume": 754374005.0
  }, 
  "links": {
    "doi": "https://doi.org/10.5281/zenodo.3553676", 
    "conceptdoi": "https://doi.org/10.5281/zenodo.3553675", 
    "bucket": "https://zenodo.org/api/files/3bcdb590-4aa4-4af3-baed-24b1382d32f9", 
    "conceptbadge": "https://zenodo.org/badge/doi/10.5281/zenodo.3553675.svg", 
    "html": "https://zenodo.org/record/3553676", 
    "latest_html": "https://zenodo.org/record/3553676", 
    "badge": "https://zenodo.org/badge/doi/10.5281/zenodo.3553676.svg", 
    "latest": "https://zenodo.org/api/records/3553676"
  }, 
  "conceptdoi": "10.5281/zenodo.3553675", 
  "created": "2019-11-26T12:51:17.740585+00:00", 
  "updated": "2020-01-20T16:44:48.918266+00:00", 
  "conceptrecid": "3553675", 
  "revision": 4, 
  "id": 3553676, 
  "metadata": {
    "access_right_category": "success", 
    "doi": "10.5281/zenodo.3553676", 
    "description": "<p>In recent years there is a surge of serialization-based vulnerabilities in web applications which have led to serious incidents, exposing private data of millions of individuals. Although there have been some efforts in addressing this problem, there is still no unified solution that is able to detect implementation-agnostic vulnerabilities. We aim to fill this gap by proposing ObjectMap, an extendable tool for the detection of deserialization and object injection vulnerabilities in Java and PHP based web applications. Furthermore, we also introduce the first deserialization test environment which can be used to test deserialization vulnerability detection tools and for educational purposes. Both of these tools are easily extendable and the first to implement this combination of features to the best of our knowledge and they bring together a synthesis of cross-complementing functionalities that are able to ignite further research in the field and help in the development of more feature-rich solutions.</p>", 
    "language": "eng", 
    "title": "[Preprint] ObjectMap: Detecting Insecure Object Deserialization", 
    "license": {
      "id": "CC-BY-4.0"
    }, 
    "notes": "This work was supported by the European Commission, under the FutureTPM, CUREX, INCOGNITO and SECONDO projects; Grant Agreements no. 779391, 826404, 824015 and 823997, respectively.", 
    "relations": {
      "version": [
        {
          "count": 1, 
          "index": 0, 
          "parent": {
            "pid_type": "recid", 
            "pid_value": "3553675"
          }, 
          "is_last": true, 
          "last_child": {
            "pid_type": "recid", 
            "pid_value": "3553676"
          }
        }
      ]
    }, 
    "communities": [
      {
        "id": "futuretpm-h2020"
      }
    ], 
    "grants": [
      {
        "code": "824015", 
        "links": {
          "self": "https://zenodo.org/api/grants/10.13039/501100000780::824015"
        }, 
        "title": "IdeNtity verifiCatiOn with privacy-preservinG credeNtIals for anonymous access To Online services", 
        "acronym": "INCOGNITO", 
        "program": "H2020", 
        "funder": {
          "doi": "10.13039/501100000780", 
          "acronyms": [], 
          "name": "European Commission", 
          "links": {
            "self": "https://zenodo.org/api/funders/10.13039/501100000780"
          }
        }
      }, 
      {
        "code": "826404", 
        "links": {
          "self": "https://zenodo.org/api/grants/10.13039/501100000780::826404"
        }, 
        "title": "seCUre and pRivate hEalth data eXchange", 
        "acronym": "CUREX", 
        "program": "H2020", 
        "funder": {
          "doi": "10.13039/501100000780", 
          "acronyms": [], 
          "name": "European Commission", 
          "links": {
            "self": "https://zenodo.org/api/funders/10.13039/501100000780"
          }
        }
      }, 
      {
        "code": "823997", 
        "links": {
          "self": "https://zenodo.org/api/grants/10.13039/501100000780::823997"
        }, 
        "title": "a Security ECONomics service platform for smart security investments and cyber insurance pricing in the beyonD 2020 netwOrking era", 
        "acronym": "SECONDO", 
        "program": "H2020", 
        "funder": {
          "doi": "10.13039/501100000780", 
          "acronyms": [], 
          "name": "European Commission", 
          "links": {
            "self": "https://zenodo.org/api/funders/10.13039/501100000780"
          }
        }
      }, 
      {
        "code": "779391", 
        "links": {
          "self": "https://zenodo.org/api/grants/10.13039/501100000780::779391"
        }, 
        "title": "Future Proofing the Connected World: A Quantum-Resistant Trusted Platform Module", 
        "acronym": "FutureTPM", 
        "program": "H2020", 
        "funder": {
          "doi": "10.13039/501100000780", 
          "acronyms": [], 
          "name": "European Commission", 
          "links": {
            "self": "https://zenodo.org/api/funders/10.13039/501100000780"
          }
        }
      }
    ], 
    "keywords": [
      "insecure deserialization", 
      "web application", 
      "security", 
      "vulnerability scanner"
    ], 
    "publication_date": "2019-11-29", 
    "creators": [
      {
        "affiliation": "University of Piraeus", 
        "name": "Koutroumpouchos Nikolaos"
      }, 
      {
        "affiliation": "University of Piraeus", 
        "name": "Lavdanis Georgios"
      }, 
      {
        "affiliation": "University of Piraeus", 
        "name": "Veroni Eleni"
      }, 
      {
        "affiliation": "University of Piraeus", 
        "name": "Ntantogian Christoforos"
      }, 
      {
        "affiliation": "University of Piraeus", 
        "name": "Xenakis Christos"
      }
    ], 
    "access_right": "open", 
    "resource_type": {
      "subtype": "preprint", 
      "type": "publication", 
      "title": "Preprint"
    }, 
    "related_identifiers": [
      {
        "scheme": "doi", 
        "identifier": "10.5281/zenodo.3553675", 
        "relation": "isVersionOf"
      }
    ]
  }
}
69
1,463
views
downloads
All versions This version
Views 6969
Downloads 1,4631,463
Data volume 754.4 MB754.4 MB
Unique views 5858
Unique downloads 1,3911,391

Share

Cite as