5 ms·
A high-performance, zero allocation, dynamic JSON Threat Protection in pure Go
- zemnmez 7y agowhat is a 'json threat'? What is the threat actor here? It seems like you do some depth / length checks on arrays and objects but it also 'validate's json somehow? https://github.com/ankur-anand/gojtp/blob/master/jtp.go#L341 https://github.com/ankur-anand/gojtp/blob/master/jtp.go#L341
- ankuranand 7y agoJavaScript object notation(JSON) is vulnerable to content level attacks. Such attacks attempt to use huge json files to overwhelm the parser and eventually crash the service. JSON threat protection is terms that describe the way to minimize the risk from such attacks by defining few limits on the json structure. Yes It also validates the json.
- zemnmez 7y agoif the idea is "limit the size of JSON" you already have http.MaxBytesReader or io.LimitReader
- eloff 7y agoThe author should describe this more clearly, without jargon or the word threat which seems an odd choice in this case. I had to read the whole readme to figure out it does length and depth validation on a json payload. Hopefully it handles streaming data.
- tedunangst 7y agoAll of the validation functions work on []byte. The io.Reader function is unimplemented.
- ankuranand 7y agoThanks for feedback, while "JSON Threat Protection" is also a quite used terminology, but yes would provide an description with common word too. Currently Streaming handling is in progress.
- hartator 7y agoJSON threat? Like overflow of requests?
- ankuranand 7y agoJavaScript object notation(JSON) is vulnerable to content level attacks. Such attacks attempt to use huge json files to overwhelm the parser and eventually crash the service. JSON threat protection is terms that describe the way to minimize the risk from such attacks by defining few limits on the json structure.
- nitwit005 7y agoIt doesn't allocate itself, but it effectively forces a big allocation by only supporting []byte inputs. Typically people directly pass the request body to json.NewDecoder, as it implements the Reader interface.
- ankuranand 7y agoThere is `func (v Verify) Verify(reader io.Reader) (bool, error)` function in the api, which will support the streaming part. Currently it's WIP.
- ankuranand 7y agoWhat is JSON Threat Protection? JSON requests are susceptible to attacks characterized by unusual inflation of elements and nesting levels. Attackers use recursive techniques to consume memory resources by using huge json files to overwhelm the parser and eventually crash the service. JSON threat protection is terms that describe the way to minimize the risk from such attacks by defining few limits on the json structure like length and depth validation on a json, and helps protect your applications from such intrusions.
- rurban 7y agoThis should be the parsers job, not an external validation service. Those threats are very parser specific.
- tomohawk 7y agoThere are situations where you do not want to parse the JSON, but do want to ensure that the JSON is not going to cause a problem. Such as a gateway. It would be a PITA for the gateway to have to know all JSON schema of all services it is protecting. There are XML validators that that perform similar functions.
- deleted 7y ago[deleted]
- conradludgate 7y agoFrom the description, I'm guessing that using a specific object json parser (such as https://github.com/mailru/easyjson https://github.com/mailru/easyjson ) would not be vulnerable to such attacks. They will just skip characters if the field is not found. And if a nested field is found inplace of a non nested one, they'll just error
- q3k 7y agoI don't get it. Are there really parsers that will allocate anything more than O(n) memory for a given maliciously crafted payload? Are there any examples/studies of this? It seems that limiting your marshaled input size to something sensible for your application should do the trick just fine for most cases.