2021
DOI: 10.48550/arxiv.2110.01005
|View full text |Cite
Preprint
|
Sign up to set email alerts
|

Cerberus: Query-driven Scalable Vulnerability Detection in OAuth Service Provider Implementations

Tamjid Al Rahat,
Yu Feng,
Yuan Tian

Abstract: OAuth protocols have been widely adopted to simplify user authentication and service authorization for thirdparty applications. However, little effort has been devoted to automatically checking the security of libraries that are widely used by service providers. In this paper, we formalize the OAuth specifications and security best practices, and design OAuthShield, an automated static analyzer, to find logical flaws and identify vulnerabilities in the implementation of OAuth authorization server libraries. To… Show more

Help me understand this report
View published versions

Search citation statements

Order By: Relevance

Paper Sections

Select...

Citation Types

0
0
0

Publication Types

Select...

Relationship

0
0

Authors

Journals

citations
Cited by 0 publications
references
References 12 publications
(15 reference statements)
0
0
0
Order By: Relevance

No citations

Set email alert for when this publication receives citations?