Efficient and extensible security enforcement using dynamic data flow analysis

Efficient and extensible security enforcement using dynamic data flow analysis
复制标题

DOI:
10.1145/1455770.1455778
复制
发表时间:
2008-10
期刊:
Proceedings of the 15th ACM conference on Computer and communications security
影响因子:
--
通讯作者:
W. Chang;Brandon Streiff;Calvin Lin
W. Chang;Brandon Streiff;Calvin Lin
中科院分区:
其他
文献类型:
--
作者:
W. Chang;Brandon Streiff;Calvin Lin

文献摘要

被引文献

相似文献

当前的污点跟踪系统遭受高开销和缺乏通用性。在本文中,我们解决了这两个问题,一个可扩展的系统,是一个数量级更有效的比以前的软件污点跟踪系统,是完全一般的动态数据流跟踪问题。我们的系统使用编译器将不受信任的程序转换为政策执行程序,我们的系统可以很容易地重新配置,以支持新的分析和政策,而无需修改编译器或运行时系统。我们的系统使用了一个健全和复杂的静态分析,可以大大减少必须动态跟踪的数据量。对于服务器程序,我们的系统的平均开销是0.65%的污点跟踪,这是最好的基于硬件的解决方案相媲美。对于一组计算限制的基准测试,我们的系统不会产生运行时开销,因为我们的编译器可以证明没有漏洞,从而消除了动态跟踪污点的需要。在修改这些基准测试以包含格式字符串漏洞之后,我们的系统开销不到13%,比以前的最佳解决方案低6倍以上。我们展示了我们的系统的灵活性和功能,将其应用到文件泄露漏洞,污点跟踪无法处理的问题。为了防止这种漏洞,我们的系统引入了三个开源服务器程序的平均运行时开销为0.25%。
Current taint tracking systems suffer from high overhead and a lack of generality. In this paper, we solve both of these issues with an extensible system that is an order of magnitude more efficient than previous software taint tracking systems and is fully general to dynamic data flow tracking problems. Our system uses a compiler to transform untrusted programs into policy-enforcing programs, and our system can be easily reconfigured to support new analyses and policies without modifying the compiler or runtime system. Our system uses a sound and sophisticated static analysis that can dramatically reduce the amount of data that must be dynamically tracked. For server programs, our system's average overhead is 0.65% for taint tracking, which is comparable to the best hardware-based solutions. For a set of compute-bound benchmarks, our system produces no runtime overhead because our compiler can prove the absence of vulnerabilities, eliminating the need to dynamically track taint. After modifying these benchmarks to contain format string vulnerabilities, our system's overhead is less than 13%, which is over 6X lower than the previous best solutions. We demonstrate the flexibility and power of our system by applying it to file disclosure vulnerabilities, a problem that taint tracking cannot handle. To prevent such vulnerabilities, our system introduces an average runtime overhead of 0.25% for three open source server programs.