Our paper, “Counterfeit Object-Oriented Programming Vulnerabilities: An Empirical Study in Java”, got accepted for The 1st International Workshop on Mining Software Repositories Applications for Privacy and Security(MSR4P&S’ 22) co-located with ESEC/FSE 2022.
In this paper, we describe a preliminary empirical investigation of COOP attacks in real software systems caused by untrusted object deserialization. In this preliminary study, we investigated the severity of these attacks, their consequences, and how they were mitigated by developers. Furthermore, we used the findings to create a dataset of vulnerable software projects and their fixes.