Beyond Instruction Level Taint Propagation

Beyond Instruction Level Taint Propagation
复制标题

DOI:
--
复制
发表时间:
2013
期刊:
--
影响因子:
--
通讯作者:
Beng Heng Ng;Earlence Fernandes;A. Aluri;A. Prakash;Z. Yang
Beng Heng Ng;Earlence Fernandes;A. Aluri;A. Prakash;Z. Yang
中科院分区:
其他
文献类型:
--
作者:
Beng Heng Ng;Earlence Fernandes;A. Aluri;A. Prakash;Z. Yang

文献摘要

被引文献

相似文献

动态污点分析(DTA)是计算机安全研究的基础。然而,DTA的当前实现通常是低效的,因为污染信息针对每个指令传播。以前的工作建议在更高的抽象(如函数)上传播污点信息。但是,这只能通过手动检测库函数的污染规则来实现。缺乏为更高抽象级别自动创建污点传播规则的研究。为了解决研究差距,我们提出了直线代码单元(SLCU)的概念,并描述了一种技术,以减少更高的抽象功能SLCU。由于基本块等同于SLCU,因此当前的基本块概括技术可以应用于SLCU。我们提出了一个算法,自动总结污点传播SLCU没有或单指针间接,我们描述不受内存别名。初步结果表明,至少有87%的基本块(SLCU的最基本形式),从一组常见的Linux库满足这一标准。
Dynamic taint analysis (DTA) plays a fundamental role in computer security research. However, current implementations of DTA are often inefficient as taint information is propagated for each instruction. Previous work has suggested propagating taint information at higher abstractions such as functions. But, this has only been achieved by manually instrumenting taint rules for library functions. Research on automatically creating taint propagation rules for higher levels of abstraction is lacking. Towards addressing the research gap, we propose the notion of straight line code units (SLCUs) and describe a technique to reduce higher abstractions like functions to SLCUs. Since a basic block is equivalent to a SLCU, current basic block summarization techniques can be applied to SLCUs. We propose an algorithm for automatically summarizing taint propagations for SLCUs with no or single pointer indirections, which we describe to be unaffected by memory aliasing. Preliminary results indicate that at least 87% of the basic blocks (the most basic form of SLCU) from a set of common Linux libraries fulfill this criteria.