DESENSITIZATION: Privacy-Aware and Attack-Preserving Crash Report
Ren Ding, Hong Hu, Wen Xu, Taesoo Kim
摘要
—Software vendors collect crash reports from end-users to assist in the debugging and testing of their products. However, crash reports may contain users’ private information, like names and passwords, rendering the user hesitant to share the reports with developers. We need a mechanism to protect users’ privacy in crash reports on the client side while keeping sufficient information to support server-side debugging and analysis. In this paper, we propose the D ESENSITIZATION technique, which generates privacy-aware and attack-preserving crash reports from crashed executions. Our tool adopts lightweight methods to identify bug-related and attack-related data from the memory, and removes other data to protect users’ privacy. Since a large portion of the desensitized memory contains null bytes, we store crash reports in spare files to save the network bandwidth and the server-side storage. We prototype D ESENSITIZATION and apply it to a large number of crashes of real-world programs, like browsers and the JavaScript engine. The result shows that our D ESENSITIZATION technique can eliminate 80.9% of non-zero bytes from coredumps, and 49.0% from minidumps. The desensitized crash report can be 50.5% smaller than the original one, which significantly saves resources for report submission and storage. Our D ESENSITIZATION technique is a push-button solution for the privacy-aware crash report.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- ARCUS: Symbolic Root Cause Analysis of Exploits in Production SystemsCarter Yagemann, Matthew Pruett, Simon P. Chung, Kennon Bittick 等USENIX Security 2021 · 被引用 42 次
- Automated Bug Hunting With Data-Driven Symbolic Root Cause AnalysisCarter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke LeeCCS 2021 · 被引用 17 次
- SDFuzz: Target States Driven Directed FuzzingPenghui Li, Wei Meng, Chao ZhangUSENIX Security 2024 · 被引用 16 次
- Encrypted Databases Made Secure Yet MaintainableMingyu Li, Xuyang Zhao, Le Chen, Cheng Tan 等OSDI 2023 · 被引用 11 次
它引用的顶会 Paper4
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- Postmortem Program Analysis with Hardware-Enhanced Post-Crash ArtifactsJun Xu, Dongliang Mu, Xinyu Xing, Peng Liu 等USENIX Security 2017 · 被引用 55 次
- CREDAL: Towards Locating a Memory Corruption Vulnerability with Your Core DumpJun Xu, Dongliang Mu, Ping Chen, Xinyu Xing 等CCS 2016 · 被引用 48 次
- Towards Efficient Heap Overflow DiscoveryXiangkun Jia, Chao Zhang, Purui Su, Yi Yang 等USENIX Security 2017 · 被引用 36 次
相关 Paper
- Protecting Source Code Privacy When Hunting Memory BugsJielun Wu, Bing Shui, Hongcheng Fan, Shengxin Wu 等ASE 2025
- Request and Conquer: Exposing Cross-Origin Resource SizeTom van Goethem, Mathy Vanhoef, Frank Piessens, Wouter JoosenUSENIX Security 2016 · 被引用 35 次
- Not All Data are Created Equal: Data and Pointer Prioritization for Scalable Protection Against Data-Oriented AttacksSalman Ahmed, Hans Liljestrand, Hani Jamjoom, Matthew Hicks 等USENIX Security 2023
- JavaScript Zero: Real JavaScript and Zero Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel GrussNDSS 2018 · 被引用 67 次
- Enabling Client-Side Crash-Resistance to Overcome Diversification and Information HidingRobert Gawlik, Benjamin Kollenda, Philipp Koppe, Behrad Garmany 等NDSS 2016 · 被引用 77 次
