Beyond Instruction Level Taint Propagation
Beyond Instruction Level Taint Propagation
复制标题
DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
Beng Heng Ng;Earlence Fernandes;A. Aluri;A. Prakash;Z. Yang
中科院分区:
文献类型:
--
作者:
Beng Heng Ng;Earlence Fernandes;A. Aluri;A. Prakash;Z. Yang
Dynamic taint analysis (DTA) plays a fundamental role in computer security research. However, current implementations of DTA are often inefficient as taint information is propagated for each instruction. Previous work has suggested propagating taint information at higher abstractions such as functions. But, this has only been achieved by manually instrumenting taint rules for library functions. Research on automatically creating taint propagation rules for higher levels of abstraction is lacking. Towards addressing the research gap, we propose the notion of straight line code units (SLCUs) and describe a technique to reduce higher abstractions like functions to SLCUs. Since a basic block is equivalent to a SLCU, current basic block summarization techniques can be applied to SLCUs. We propose an algorithm for automatically summarizing taint propagations for SLCUs with no or single pointer indirections, which we describe to be unaffected by memory aliasing. Preliminary results indicate that at least 87% of the basic blocks (the most basic form of SLCU) from a set of common Linux libraries fulfill this criteria.