ConDySTA: Context-Aware Dynamic Supplement to Static Taint Analysis

ConDySTA: Context-Aware Dynamic Supplement to Static Taint Analysis
复制标题

DOI:
10.1109/sp40001.2021.00040
复制
发表时间:
2021-05
期刊:
2021 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Xueling Zhang;Xiaoyin Wang;Rocky Slavin;Jianwei Niu
Xueling Zhang;Xiaoyin Wang;Rocky Slavin;Jianwei Niu
中科院分区:
其他
文献类型:
--
作者:
Xueling Zhang;Xiaoyin Wang;Rocky Slavin;Jianwei Niu

文献摘要

被引文献

相似文献

静态污点分析是检测软件系统中污点流的广泛应用的技术。虽然它们在理论上是保守的,并且被设计为检测所有可能的污点流,但由于各种实现限制,静态污点分析几乎总是表现出假阴性。动态编程语言特性、不可访问的代码以及在软件项目中使用多种编程语言是一些主要原因。为了缓解这个问题,我们开发了一种新的方法,DySTA,它使用动态污点分析结果作为静态污点分析的额外来源。然而,天真地添加源会导致静态分析失去上下文敏感性,从而产生误报。因此,我们开发了一种混合上下文匹配算法和相应的工具,ConDySTA,保持上下文敏感性DySTA。我们应用了REPRODROID [1],一个全面的Android分析工具基准框架,来评估ConDySTA。结果显示,在28个应用程序中,(1)ConDySTA能够检测到28个污点流中的12个,这些污点流未被ReproDroid中考虑的6个最先进静态污点分析中的任何一个检测到,(2)ConDySTA未报告假阳性,而DySTA单独报告了9个。我们进一步将ConDySTA和FlowDroid应用于Google Play中的100个顶级Android应用程序,ConDySTA能够检测到39个额外的污点流(除了FlowDroid发现的281个污点流之外),同时保留了FlowDroid的上下文敏感性。
Static taint analyses are widely-applied techniques to detect taint flows in software systems. Although they are theoretically conservative and de-signed to detect all possible taint flows, static taint analyses almost always exhibit false negatives due to a variety of implementation limitations. Dynamic programming language features, inaccessible code, and the usage of multiple programming languages in a software project are some of the major causes. To alleviate this problem, we developed a novel approach, DySTA, which uses dynamic taint analysis results as additional sources for static taint analysis. However, naïvely adding sources causes static analysis to lose context sensitivity and thus produce false positives. Thus, we developed a hybrid context matching algorithm and corresponding tool, ConDySTA, to preserve context sensitivity in DySTA. We applied REPRODROID [1], a comprehensive benchmarking framework for Android analysis tools, to evaluate ConDySTA. The results show that across 28 apps (1) ConDySTA was able to detect 12 out of 28 taint flows which were not detected by any of the six state-of-the-art static taint analyses considered in ReproDroid, and (2) ConDySTA reported no false positives, whereas nine were reported by DySTA alone. We further applied ConDySTA and FlowDroid to 100 top Android apps from Google Play, and ConDySTA was able to detect 39 additional taint flows (besides 281 taint flows found by FlowDroid) while preserving the context sensitivity of FlowDroid.