TaintEMU: Decoupling Tracking from Functional Domains for Architecture-Agnostic and Efficient Whole-System Taint Tracking
Lei Cui, Youquan Xian, Peng Liu, Longjin Lu
Abstract
Whole-system taint tracking is vital for security analysis. However, existing methods suffer from limited architecture compatibility and significant performance overhead, mainly due to the tight coupling between the functional and tracking domains. This paper introduces TaintEMU, an architecture-agnostic and efficient solution by fully decoupling the two domains. It separates functional and tracking logic at the QEMU TCG layer, mapping shadow registers to host instead of guest registers, ensuring compatibility across guest CPU architectures. At the host layer, it physically isolates the two domains: general-purpose instructions and registers serve the functional domain, while vector resources are dedicated to tracking, avoiding host resource reuse and enhancing tracking performance. Furthermore, it directly generates tracking instructions from TCG operations on the host, bypassing additional translation and further reducing overhead. We implement TaintEMU on an AMD64 host on QEMU 8.2.2. It supports a wide range of guest architectures (x86, MIPS, ARM, AMD, RISC-V, PPC), reduces performance overhead from 301% (DECAF++) to 101% and successfully detects all vulnerabilities in tests with 8 CVEs across 7 applications.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 2afd0133-4244-4650-9be6-c1a36bdda9b0Cited by top-tier papers1
Ask how each one uses itRelated papers
- One Engine To Serve 'em All: Inferring Taint Rules Without Architectural SemanticsZheng Leong Chua, Yanhao Wang, Teodora Baluta, Prateek Saxena et al.NDSS 2019 · 40 citations
- AirTaint: Making Dynamic Taint Analysis Faster and EasierQian Sang, Yanhao Wang, Yuwei Liu, Xiangkun Jia et al.S&P 2024 · 11 citations
- HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware TracingYiyu Zhang, Tianyi Liu, Yueyang Wang, Yun Qi et al.OOPSLA 2024 · 7 citations
- Ninja: Towards Transparent Tracing and Debugging on ARMZhenyu Ning, Fengwei ZhangUSENIX Security 2017 · 62 citations
- SymQEMU: Compilation-based symbolic execution for binariesSebastian Poeplau, Aurélien FrancillonNDSS 2021
