More Haste, Less Speed: Cache Related Security Threats in Continuous Integration Services

被引:0
|
作者
Gu, Yacong [1 ,4 ]
Ying, Lingyun [2 ,4 ]
Chai, Huajun [2 ]
Pu, Yingyuan [2 ]
Duan, Haixin [1 ,4 ]
Gao, Xing [3 ]
机构
[1] Tsinghua Univ, Beijing, Peoples R China
[2] QI ANXIN Technol Res Inst, Singapore, Singapore
[3] Univ Delaware, Newark, DE USA
[4] Tsinghua Univ, QI ANXIN Grp JCNS, Beijing, Peoples R China
基金
美国国家科学基金会;
关键词
D O I
10.1109/SP54263.2024.00138
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuous Integration (CI) platforms have widely adopted caching to speed up CI task executions by storing and reusing dependent packages. Unfortunately, CI cache also exposes new attack surfaces when cache objects are shared across trust boundaries. In this paper, we systematically investigate potential security threats of CI cache features in seven mainstream CI platforms (CIPs). We find that existing CIPs have isolation issues in their cache sharing and inheritance strategies, potentially raising cache poisoning and data leakage problems. By exploiting these vulnerable mechanisms, we further uncover four attack vectors enabling attackers to stealthily inject malicious code into the cache or steal sensitive data. Even worse, many CIPs provide vulnerable official cache templates that will mistakenly store and expose sensitive data in the cache by default. To understand the potential impact of our disclosed threats, we develop an analysis tool and conduct a large-scale measurement on open-source repositories. Our measurement results show that many popular repositories are potentially affected by these attacks. We also identify 78 repositories that expose their high-value secrets in cache objects and are at risk of secret leakage. We have duly reported identified vulnerabilities to corresponding stakeholders and received positive responses.
引用
收藏
页码:1179 / 1197
页数:19
相关论文
共 50 条
  • [31] Continuous Intrusion: Characterizing the Security of Continuous Integration Services
    Gu, Yacong
    Ying, Lingyun
    Chai, Huajun
    Qiao, Chu
    Duan, Haixin
    Gao, Xing
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 1561 - 1577
  • [32] Less Haste, More Speed, More Science: Lessons to be Learned from COVID-19 Studies
    Singer, Mervyn
    AMERICAN JOURNAL OF RESPIRATORY AND CRITICAL CARE MEDICINE, 2022, 205 (11) : 1258 - 1260
  • [33] Less speed more haste: The effect of crisis response speed and information strategy on the consumer-brand relationship
    Iveson, Abbie
    Hultman, Magnus
    Davvetas, Vasileios
    Oghazi, Pejvak
    PSYCHOLOGY & MARKETING, 2023, 40 (02) : 391 - 407
  • [34] Alternative vector control methods to manage the Zika virus outbreak: more haste, less speed
    Bouyer, Jeremy
    Chandre, Fabrice
    Gilles, Jeremie
    Baldet, Thierry
    LANCET GLOBAL HEALTH, 2016, 4 (06): : E364 - E364
  • [35] More Haste, Less Speed: How Update Frequency of Mobile Apps Influences Consumer Interest
    Gong, Xuan
    Razzaq, Amar
    Wang, Wei
    JOURNAL OF THEORETICAL AND APPLIED ELECTRONIC COMMERCE RESEARCH, 2021, 16 (07): : 2922 - 2942
  • [36] More Haste, Less Speed: Could Public-Private Partnerships Advance Cellular immunotherapies?
    Bubela, Tania
    Bonter, Katherine
    Lachance, Silvy
    Delisle, Jean-Sebastien
    Gold, E. Richard
    FRONTIERS IN MEDICINE, 2017, 4
  • [37] Inflammatory Bowel Disease and the SARS-CoV-2 Pandemic: More Speed, Less Haste
    Gower-Rousseau, Corinne
    Fumery, Mathurin
    Pariente, Benjamin
    GASTROENTEROLOGY, 2021, 160 (01) : 473 - 474
  • [38] Less haste more speed: factors that prolong the interval from presentation to diagnosis in some cancers
    Jiwa, M
    Reid, J
    Handley, C
    Grimwood, J
    Ward, S
    Turner, K
    Ibbotson, M
    Thorman, N
    FAMILY PRACTICE, 2004, 21 (03) : 299 - 303
  • [39] Less Haste, More Speed: The Fit for the Future Reform Program in New South Wales Local Government
    Drew, Joseph
    Dollery, Brian
    AUSTRALIAN JOURNAL OF PUBLIC ADMINISTRATION, 2016, 75 (01) : 78 - 88
  • [40] More Haste, Less Speed? An Evaluation of Fast Track Policies to Tackle Persistent Youth Offending in Scotland
    Hill, Malcolm
    Walker, Moira
    Moodie, Kristina
    Wallace, Brendan
    Bannister, Jon
    Khan, Furzana
    McIvor, Gill
    Kendrick, Andrew
    YOUTH JUSTICE-AN INTERNATIONAL JOURNAL, 2007, 7 (02): : 121 - 138