USENIX Security2026Top-tier venue
MULCOTAINT: Towards Efficient Multi-tag Dynamic Taint Analysis via Hardware/Software Co-design
Bing Qi, Yi Yang, Xiangkun Jia, Zhengpin Qian, Huafeng Huang, Purui Su
Abstract
Multi-tag dynamic taint analysis (M-DTA) is critical in fine-grained analysis scenarios such as vulnerability analysis. However, current software solutions have serious performance problems. Although hardware solutions are promising, they are single-tag and difficult to extend to M-DTA. We propose an efficient M-DTA framework named MULCOTAINT via hardware/software co-design. We decouple the taint analysis from the normal execution with the coprocessor architecture and solve several challenges, such as designing taint calculation as vectorized calculation, managing taint tags with page tables, and providing functionality interfaces of the taint analysis engine. We build a dataset of 32 programs with 5 types and conduct the performance evaluation and vulnerability analysis experiments. The results show that MULCOTAINT has high performance and acceptable memory usage with abilities of detailed vulnerability analysis. MULCOTAINT outperforms the software solutions (TaintRabbit and PANDA) and hardware solutions (HardTaint, RAFT, and FineDIFT). The maximum difference of overhead increase based on the respective baselines could be '1.14x vs. 4409.09x' for 'MULCOTAINT vs. PANDA', while HardTaint's average overhead increase is 19.57 times that of MULCOTAINT. Although the prototype of MULCOTAINT's hardware cost is higher than embedded-oriented works RAFT and FineDIFT, it is acceptable due to M-DTA's complex logic.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 15f3864d-25ba-4eb7-b747-684f06dee7ffBuilds on12
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- Capturing Malware Propagations with Code Injections and Code-Reuse AttacksDavid Korczynski, Heng YinCCS 2017 · 57 citations
- SelectiveTaint: Efficient Data Flow Tracking With Static Binary RewritingSanchuan Chen, Zhiqiang Lin, Yinqian ZhangUSENIX Security 2021 · 45 citations
- Towards Efficient Heap Overflow DiscoveryXiangkun Jia, Chao Zhang, Purui Su, Yi Yang et al.USENIX Security 2017 · 36 citations
Related papers
- HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware TracingYiyu Zhang, Tianyi Liu, Yueyang Wang, Yun Qi et al.OOPSLA 2024 · 7 citations
- AirTaint: Making Dynamic Taint Analysis Faster and EasierQian Sang, Yanhao Wang, Yuwei Liu, Xiangkun Jia et al.S&P 2024 · 11 citations
- Faster and Better: Detecting Vulnerabilities in Linux-based IoT Firmware with Optimized Reaching Definition AnalysisZicong Gao, Chao Zhang, Hangtian Liu, Wenhou Sun et al.NDSS 2024
- Neutaint: Efficient Dynamic Taint Analysis with Neural NetworksDongdong She, Yizheng Chen, Abhishek Shah, Baishakhi Ray et al.S&P 2020 · 54 citations
- TaintEMU: Decoupling Tracking from Functional Domains for Architecture-Agnostic and Efficient Whole-System Taint TrackingLei Cui, Youquan Xian, Peng Liu, Longjin LuASPLOS 2025 · 1 citation
