Paralegal: Practical Static Analysis for Privacy Bugs
Justus Adam, Carolyn Zech, Livia Zhu, Sreshtaa Rajesh, Nathan Harbison, Mithi Jethwa, Will Crichton, Shriram Krishnamurthi, Malte Schwarzkopf
Abstract
Finding privacy bugs in software today usually requires onerous manual audits. Code analysis tools could help, but existing tools aren't sufficiently practical and ergonomic to be used.
Paralegal is a static analysis tool to find privacy bugs in Rust programs. Key to Paralegal's practicality is its distribution of work between the program analyzer, privacy engineers, and application developers. Privacy engineers express a high-level privacy policy over markers, which application developers then apply to source code entities. Paralegal extracts a Program Dependence Graph (PDG) from the program, leveraging Rust's ownership type system to model the behavior of library code. Paralegal augments the PDG with the developers' markers and checks privacy policies against the marked PDG.
In an evaluation on eight real-world applications, Paralegal found real privacy bugs, including two previously unknown ones. Paralegal supports a broader range of policies than information flow control (IFC) and CodeQL, a widely-used code analysis engine. Paralegal is fast enough to deploy interactively, and its markers are easy to maintain as code evolves.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 523f3a76-1dfb-4147-9633-a00b484d1773Cited by top-tier papers1
Ask how each one uses itBuilds on17
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
- Qapla: Policy compliance for database-backed systemsAastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg et al.USENIX Security 2017 · 46 citations
- STORM: Refinement Types for Secure Web ApplicationsNico Lehmann, Rose Kunkel, Jordan Brown, Jean Yang et al.OSDI 2021 · 21 citations
- Model Checking Guided Testing for Distributed SystemsDong Wang, Wensheng Dou, Yu Gao, Chenao Wu et al.EuroSys 2023 · 21 citations
Related papers
- A Study of Undefined Behavior Across Foreign Function Boundaries in Rust LibrariesIan McCormack, Joshua Sunshine, Jonathan AldrichICSE 2025 · 5 citations
- Rudra: Finding Memory Safety Bugs in Rust at the Ecosystem ScaleYechan Bae, Youngsuk Kim, Ammar Askar, Jungwon Lim et al.SOSP 2021 · 61 citations
- Rusted Types: Static Detection of Rust Type Confusion BugsZeyang Zhuang, Wei Meng, Michael R. LyuICSE 2026
- Modular information flow through ownershipWill Crichton, Marco Patrignani, Maneesh Agrawala, Pat HanrahanPLDI 2022 · 13 citations
- PrivGuard: Privacy Regulation Compliance Made EasierLun Wang, Usmann Khan, Joseph P. Near, Qi Pang et al.USENIX Security 2022
