MULCOTAINT: Towards Efficient Multi-tag Dynamic Taint Analysis via Hardware/Software Co-design
Bing Qi, Yi Yang, Xiangkun Jia, Zhengpin Qian, Huafeng Huang, Purui Su
摘要
Multi-tag dynamic taint analysis (M-DTA) is critical in fine-grained analysis scenarios such as vulnerability analysis. However, current software solutions have serious performance problems. Although hardware solutions are promising, they are single-tag and difficult to extend to M-DTA. We propose an efficient M-DTA framework named MULCOTAINT via hardware/software co-design. We decouple the taint analysis from the normal execution with the coprocessor architecture and solve several challenges, such as designing taint calculation as vectorized calculation, managing taint tags with page tables, and providing functionality interfaces of the taint analysis engine. We build a dataset of 32 programs with 5 types and conduct the performance evaluation and vulnerability analysis experiments. The results show that MULCOTAINT has high performance and acceptable memory usage with abilities of detailed vulnerability analysis. MULCOTAINT outperforms the software solutions (TaintRabbit and PANDA) and hardware solutions (HardTaint, RAFT, and FineDIFT). The maximum difference of overhead increase based on the respective baselines could be '1.14x vs. 4409.09x' for 'MULCOTAINT vs. PANDA', while HardTaint's average overhead increase is 19.57 times that of MULCOTAINT. Although the prototype of MULCOTAINT's hardware cost is higher than embedded-oriented works RAFT and FineDIFT, it is acceptable due to M-DTA's complex logic.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik 等NDSS 2019 · 被引用 413 次
- Capturing Malware Propagations with Code Injections and Code-Reuse AttacksDavid Korczynski, Heng YinCCS 2017 · 被引用 57 次
- SelectiveTaint: Efficient Data Flow Tracking With Static Binary RewritingSanchuan Chen, Zhiqiang Lin, Yinqian ZhangUSENIX Security 2021 · 被引用 45 次
- Towards Efficient Heap Overflow DiscoveryXiangkun Jia, Chao Zhang, Purui Su, Yi Yang 等USENIX Security 2017 · 被引用 36 次
相关 Paper
- HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware TracingYiyu Zhang, Tianyi Liu, Yueyang Wang, Yun Qi 等OOPSLA 2024 · 被引用 7 次
- AirTaint: Making Dynamic Taint Analysis Faster and EasierQian Sang, Yanhao Wang, Yuwei Liu, Xiangkun Jia 等S&P 2024 · 被引用 11 次
- Faster and Better: Detecting Vulnerabilities in Linux-based IoT Firmware with Optimized Reaching Definition AnalysisZicong Gao, Chao Zhang, Hangtian Liu, Wenhou Sun 等NDSS 2024
- Neutaint: Efficient Dynamic Taint Analysis with Neural NetworksDongdong She, Yizheng Chen, Abhishek Shah, Baishakhi Ray 等S&P 2020 · 被引用 54 次
- TaintEMU: Decoupling Tracking from Functional Domains for Architecture-Agnostic and Efficient Whole-System Taint TrackingLei Cui, Youquan Xian, Peng Liu, Longjin LuASPLOS 2025 · 被引用 1 次
