【24h】

TWalker: An efficient taint analysis tool

机译:TWalker:高效的污点分析工具

获取原文

摘要

The taint analysis method is usually effective for vulnerabilities detection. Existing works mostly care about the accuracy of taint propagation, not considering the time cost. We proposed a novel method to improve the efficiency of taint propagation with indices. Based our method, we have implemented TWalker, an effective vulnerabilities detection tool that enables easy data flow analysis of the real world programs, providing faster taint analysis than other existing works. TWalker has four properties: first, it works directly on the programs without source code; second, it monitors the program's execution and records its necessary context; third, it delivers fine-grained taint analysis, providing fast taint propagation with indices; fourth, it could detect vulnerabilities effectively based on two security property rules. We have evaluated TWalker with several real world programs and compared it with a typical taint analysis tool. The experimental results show that our tool could perform taint propagation much faster than other tool, having better ability for vulnerabilities detection.
机译:污点分析方法通常对漏洞检测有效。现有作品主要关注污点传播的准确性,而不考虑时间成本。我们提出了一种新的方法来提高带有索引的污点传播的效率。基于我们的方法,我们实现了TWalker,这是一种有效的漏洞检测工具,可以轻松地对现实程序进行数据流分析,比其他现有作品提供更快的污染分析。 TWalker具有四个属性:首先,它可以直接在没有源代码的程序上工作;其次,它监视程序的执行并记录其必要的上下文;第三,它提供细粒度的污点分析,提供带有索引的污点快速传播;第四,它可以基于两个安全属性规则来有效地检测漏洞。我们已经用几个真实的程序对TWalker进行了评估,并将其与典型的污点分析工具进行了比较。实验结果表明,我们的工具可以比其他工具更快地执行污点传播,具有更好的漏洞检测能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号