USENIX Security2021Top-tier venue
FlowDist: Multi-Staged Refinement-Based Dynamic Information Flow Analysis for Distributed Software Systems
Xiaoqin Fu, Haipeng Cai
Abstract
Dynamic information flow analysis (DIFA) supports various security applications such as malware analysis and vulnerability discovery. Yet traditional DIFA approaches have limited utility for distributed software due to applicability, portability, and scalability barriers. We present FLOWDIST, a DIFA for common distributed software that overcomes these challenges. FLOWDIST works at purely application level to avoid platform customizations hence achieve high portability. It infers implicit, interprocess dependencies from global partially ordered execution events to address applicability to distributed software. Most of all, it introduces a multi-staged refinement-based scheme for application-level DIFA, where an otherwise expensive data flow analysis is reduced by method-level results from a cheap pre-analysis, to achieve high scalability while remaining effective. Our evaluation of FLOWDIST on 12 real-world distributed systems against two peer tools revealed its superior effectiveness with practical efficiency and scalability. It has found 18 known and 24 new vulnerabilities, with 17 confirmed and 2 fixed. We also present and evaluate two alternative designs of FLOWDIST for both design justification and diverse subject accommodations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4f36b52f-cf21-47b0-863f-a2cfbe8113f8Cited by top-tier papers11
- VULGEN: Realistic Vulnerability Generation Via Pattern Mining and Deep LearningYu Nong, Yuzhe Ou, Michael Pradel, Feng Chen et al.ICSE 2023 · 32 citations
- VGX: Large-Scale Sample Generation for Boosting Learning-Based Software Vulnerability AnalysesYu Nong, Richard Fang, Guangbei Yi, Kunsong Zhao et al.ICSE 2024 · 23 citations
- Generating realistic vulnerabilities via neural code editing: an empirical studyYu Nong, Yuzhe Ou, Michael Pradel, Feng Chen et al.FSE 2022 · 23 citations
- On the vulnerability proneness of multilingual codeWen Li, Li Li, Haipeng CaiFSE 2022 · 22 citations
- Model Checking Guided Testing for Distributed SystemsDong Wang, Wensheng Dou, Yu Gao, Chenao Wu et al.EuroSys 2023 · 21 citations
Builds on3
- Neutaint: Efficient Dynamic Taint Analysis with Neural NetworksDongdong She, Yizheng Chen, Abhishek Shah, Baishakhi Ray et al.S&P 2020 · 54 citations
- Effective Concurrency Testing for Distributed SystemsXinhao Yuan, Junfeng YangASPLOS 2020 · 30 citations
- Iodine: Fast Dynamic Taint Tracking Using Rollback-free Optimistic Hybrid AnalysisSubarno Banerjee, David Devecsery, Peter M. Chen, Satish NarayanasamyS&P 2019 · 27 citations
Related papers
- PolyCruise: A Cross-Language Dynamic Information Flow AnalysisWen Li, Jiang Ming, Xiapu Luo, Haipeng CaiUSENIX Security 2022
- Two-Level Adaptation for Budget-Constrained Continuous Dynamic Dependence AnalysisXiaoqin Fu, Haipeng CaiFSE 2026
- FlowMatrix: GPU-Assisted Information-Flow Analysis through Matrix-Based RepresentationKaihang Ji, Jun Zeng, Yuancheng Jiang, Zhenkai Liang et al.USENIX Security 2022
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen et al.CCS 2018 · 93 citations
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 1 citation
