• DocumentCode
    3699096
  • Title

    Analyst-oriented taint analysis by taint path slicing and aggregation

  • Author

    Jinkun Pan;Xiaoguang Mao;Weishi Li

  • Author_Institution
    College of Computer, National University of Defense Technology, Changsha, Hunan Province, China
  • fYear
    2015
  • Firstpage
    145
  • Lastpage
    148
  • Abstract
    Taint analysis determines whether values from untrusted or private sources may flow into security-sensitive or public sinks, and can discover many common security vulnerabilities in both Web and mobile applications. Static taint analysis detects suspicious data flows without running the application and achieves a good coverage. However, most existing static taint analysis tools only focus on discovering taint paths from sources to sinks and do not concern about the requirements of analysts for sanitization check and exploration. The sanitization can make a taint path no more dangerous but should be checked or explored by analysts manually in many cases and the process is very costly. During our preliminary study, we found that many statements along taint paths are not relevant to the sanitization and there are a lot of redundancies among taint paths with the same source or sink. Based on these two observations, we have designed and implemented the taint path slicing and aggregation algorithms, aiming at mitigating the workload of the analysts and helping them get a better comprehension of the taint behaviors of target applications. Experimental evaluations on real-world applications show that our proposed algorithms can reduce the taint paths effectively and efficiently.
  • Keywords
    "Redundancy","Algorithm design and analysis","Androids","Humanoid robots","Security","Mobile applications","Filtering"
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering and Service Science (ICSESS), 2015 6th IEEE International Conference on
  • ISSN
    2327-0586
  • Print_ISBN
    978-1-4799-8352-0
  • Electronic_ISBN
    2327-0594
  • Type

    conf

  • DOI
    10.1109/ICSESS.2015.7339024
  • Filename
    7339024