Sleeping Giants -- Activating Dormant Java Deserialization Gadget Chains through Stealthy Code Changes
Fuente:
arXiv
Saved in:
| Main Authors: | Kreyssig, Bruno, Houy, Sabine, Riom, Timothée, Bartel, Alexandre |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Deserialization Gadget Chains are not a Pathological Problem in Android:an In-Depth Study of Java Gadget Chains in AOSP
by: Kreyssig, Bruno, et al.
Published: (2025)
by: Kreyssig, Bruno, et al.
Published: (2025)
In the Magma chamber: Update and challenges in ground-truth vulnerabilities revival for automatic input generator comparison
by: Riom, Timothée, et al.
Published: (2025)
by: Riom, Timothée, et al.
Published: (2025)
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
by: Houy, Sabine, et al.
Published: (2025)
by: Houy, Sabine, et al.
Published: (2025)
CFIghter: Automated Control-Flow Integrity Enablement and Evaluation for Legacy C/C++ Systems
by: Houy, Sabine, et al.
Published: (2025)
by: Houy, Sabine, et al.
Published: (2025)
Detecting Stealthy Data Poisoning Attacks in AI Code Generators
by: Improta, Cristina
Published: (2025)
by: Improta, Cristina
Published: (2025)
Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
by: Dong, Ben, et al.
Published: (2026)
by: Dong, Ben, et al.
Published: (2026)
FLAMES: Fine-tuning LLMs to Synthesize Invariants for Smart Contract Security
by: Eshghie, Mojtaba, et al.
Published: (2025)
by: Eshghie, Mojtaba, et al.
Published: (2025)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
by: Jiang, Wenxin, et al.
Published: (2025)
by: Jiang, Wenxin, et al.
Published: (2025)
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
by: Štorek, Adam, et al.
Published: (2025)
by: Štorek, Adam, et al.
Published: (2025)
Classport: Designing Runtime Dependency Introspection for Java
by: Cofano, Serena, et al.
Published: (2025)
by: Cofano, Serena, et al.
Published: (2025)
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025)
by: Wang, Junjie, et al.
Published: (2025)
Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java Projects
by: Schott, Stefan, et al.
Published: (2025)
by: Schott, Stefan, et al.
Published: (2025)
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
by: Schmid, Larissa, et al.
Published: (2025)
by: Schmid, Larissa, et al.
Published: (2025)
PPT4J: Patch Presence Test for Java Binaries
by: Pan, Zhiyuan, et al.
Published: (2023)
by: Pan, Zhiyuan, et al.
Published: (2023)
Exploring Security Practices in Infrastructure as Code: An Empirical Study
by: Verdet, Alexandre, et al.
Published: (2023)
by: Verdet, Alexandre, et al.
Published: (2023)
Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
by: Schott, Stefan, et al.
Published: (2026)
by: Schott, Stefan, et al.
Published: (2026)
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
by: Ferenc, Rudolf, et al.
Published: (2024)
by: Ferenc, Rudolf, et al.
Published: (2024)
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
by: Moreno, José Miguel, et al.
Published: (2024)
by: Moreno, José Miguel, et al.
Published: (2024)
From Struggle to Simplicity with a Usable and Secure API for Encryption in Java
by: Firouzi, Ehsan, et al.
Published: (2024)
by: Firouzi, Ehsan, et al.
Published: (2024)
Coverage-Guided Multi-Agent Harness Generation for Java Library Fuzzing
by: Loose, Nils, et al.
Published: (2026)
by: Loose, Nils, et al.
Published: (2026)
DeCoMa: Detecting and Purifying Code Dataset Watermarks through Dual Channel Code Abstraction
by: Xiao, Yuan, et al.
Published: (2025)
by: Xiao, Yuan, et al.
Published: (2025)
Cybersecurity Defenses: Exploration of CVE Types through Attack Descriptions
by: Othman, Refat, et al.
Published: (2024)
by: Othman, Refat, et al.
Published: (2024)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
by: Zhou, Dongchao, et al.
Published: (2025)
by: Zhou, Dongchao, et al.
Published: (2025)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
by: Xia, Yifan, et al.
Published: (2023)
by: Xia, Yifan, et al.
Published: (2023)
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
by: Chen, Zirui, et al.
Published: (2026)
by: Chen, Zirui, et al.
Published: (2026)
FDI: Attack Neural Code Generation Systems through User Feedback Channel
by: Sun, Zhensu, et al.
Published: (2024)
by: Sun, Zhensu, et al.
Published: (2024)
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge
by: Lu, Tianhe, et al.
Published: (2026)
by: Lu, Tianhe, et al.
Published: (2026)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
by: Seth, Aishwarya, et al.
Published: (2023)
by: Seth, Aishwarya, et al.
Published: (2023)
WildCode: An Empirical Analysis of Code Generated by ChatGPT
by: Khanmohammadi, Kobra, et al.
Published: (2025)
by: Khanmohammadi, Kobra, et al.
Published: (2025)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
How to Compare the Security of Code Written by Humans to LLM-generated Code
by: Balebako, Rebecca, et al.
Published: (2026)
by: Balebako, Rebecca, et al.
Published: (2026)
SecCodePRM: A Process Reward Model for Code Security
by: Yu, Weichen, et al.
Published: (2026)
by: Yu, Weichen, et al.
Published: (2026)
Unsupervised Binary Code Translation with Application to Code Similarity Detection and Vulnerability Discovery
by: Ahmad, Iftakhar, et al.
Published: (2024)
by: Ahmad, Iftakhar, et al.
Published: (2024)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
On-Chain Analysis of Smart Contract Dependency Risks on Ethereum
by: Jin, Monica, et al.
Published: (2025)
by: Jin, Monica, et al.
Published: (2025)
Dirty-Waters: Detecting Software Supply Chain Smells
by: Liu, Raphina, et al.
Published: (2024)
by: Liu, Raphina, et al.
Published: (2024)
Similar Items
-
Deserialization Gadget Chains are not a Pathological Problem in Android:an In-Depth Study of Java Gadget Chains in AOSP
by: Kreyssig, Bruno, et al.
Published: (2025) -
In the Magma chamber: Update and challenges in ground-truth vulnerabilities revival for automatic input generator comparison
by: Riom, Timothée, et al.
Published: (2025) -
A Practical Guideline and Taxonomy to LLVM's Control Flow Integrity
by: Houy, Sabine, et al.
Published: (2025) -
CFIghter: Automated Control-Flow Integrity Enablement and Evaluation for Legacy C/C++ Systems
by: Houy, Sabine, et al.
Published: (2025) -
Detecting Stealthy Data Poisoning Attacks in AI Code Generators
by: Improta, Cristina
Published: (2025)