DESENSITIZATION: Privacy-Aware and Attack-Preserving Crash Report
Ren Ding, Hong Hu, Wen Xu, Taesoo Kim
Abstract
—Software vendors collect crash reports from end-users to assist in the debugging and testing of their products. However, crash reports may contain users’ private information, like names and passwords, rendering the user hesitant to share the reports with developers. We need a mechanism to protect users’ privacy in crash reports on the client side while keeping sufficient information to support server-side debugging and analysis. In this paper, we propose the D ESENSITIZATION technique, which generates privacy-aware and attack-preserving crash reports from crashed executions. Our tool adopts lightweight methods to identify bug-related and attack-related data from the memory, and removes other data to protect users’ privacy. Since a large portion of the desensitized memory contains null bytes, we store crash reports in spare files to save the network bandwidth and the server-side storage. We prototype D ESENSITIZATION and apply it to a large number of crashes of real-world programs, like browsers and the JavaScript engine. The result shows that our D ESENSITIZATION technique can eliminate 80.9% of non-zero bytes from coredumps, and 49.0% from minidumps. The desensitized crash report can be 50.5% smaller than the original one, which significantly saves resources for report submission and storage. Our D ESENSITIZATION technique is a push-button solution for the privacy-aware crash report.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 198e8e7b-87b8-4f55-a73f-63a5bb09853cCited by top-tier papers4
- ARCUS: Symbolic Root Cause Analysis of Exploits in Production SystemsCarter Yagemann, Matthew Pruett, Simon P. Chung, Kennon Bittick et al.USENIX Security 2021 · 42 citations
- Automated Bug Hunting With Data-Driven Symbolic Root Cause AnalysisCarter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke LeeCCS 2021 · 17 citations
- SDFuzz: Target States Driven Directed FuzzingPenghui Li, Wei Meng, Chao ZhangUSENIX Security 2024 · 16 citations
- Encrypted Databases Made Secure Yet MaintainableMingyu Li, Xuyang Zhao, Le Chen, Cheng Tan et al.OSDI 2023 · 11 citations
Builds on4
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Postmortem Program Analysis with Hardware-Enhanced Post-Crash ArtifactsJun Xu, Dongliang Mu, Xinyu Xing, Peng Liu et al.USENIX Security 2017 · 55 citations
- CREDAL: Towards Locating a Memory Corruption Vulnerability with Your Core DumpJun Xu, Dongliang Mu, Ping Chen, Xinyu Xing et al.CCS 2016 · 48 citations
- Towards Efficient Heap Overflow DiscoveryXiangkun Jia, Chao Zhang, Purui Su, Yi Yang et al.USENIX Security 2017 · 36 citations
Related papers
- Protecting Source Code Privacy When Hunting Memory BugsJielun Wu, Bing Shui, Hongcheng Fan, Shengxin Wu et al.ASE 2025
- Request and Conquer: Exposing Cross-Origin Resource SizeTom van Goethem, Mathy Vanhoef, Frank Piessens, Wouter JoosenUSENIX Security 2016 · 35 citations
- Not All Data are Created Equal: Data and Pointer Prioritization for Scalable Protection Against Data-Oriented AttacksSalman Ahmed, Hans Liljestrand, Hani Jamjoom, Matthew Hicks et al.USENIX Security 2023
- JavaScript Zero: Real JavaScript and Zero Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel GrussNDSS 2018 · 67 citations
- Enabling Client-Side Crash-Resistance to Overcome Diversification and Information HidingRobert Gawlik, Benjamin Kollenda, Philipp Koppe, Behrad Garmany et al.NDSS 2016 · 77 citations
