TaintEMU: Decoupling Tracking from Functional Domains for Architecture-Agnostic and Efficient Whole-System Taint Tracking
Lei Cui, Youquan Xian, Peng Liu, Longjin Lu
摘要
Whole-system taint tracking is vital for security analysis. However, existing methods suffer from limited architecture compatibility and significant performance overhead, mainly due to the tight coupling between the functional and tracking domains. This paper introduces TaintEMU, an architecture-agnostic and efficient solution by fully decoupling the two domains. It separates functional and tracking logic at the QEMU TCG layer, mapping shadow registers to host instead of guest registers, ensuring compatibility across guest CPU architectures. At the host layer, it physically isolates the two domains: general-purpose instructions and registers serve the functional domain, while vector resources are dedicated to tracking, avoiding host resource reuse and enhancing tracking performance. Furthermore, it directly generates tracking instructions from TCG operations on the host, bypassing additional translation and further reducing overhead. We implement TaintEMU on an AMD64 host on QEMU 8.2.2. It supports a wide range of guest architectures (x86, MIPS, ARM, AMD, RISC-V, PPC), reduces performance overhead from 301% (DECAF++) to 101% and successfully detects all vulnerabilities in tests with 8 CVEs across 7 applications.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- One Engine To Serve 'em All: Inferring Taint Rules Without Architectural SemanticsZheng Leong Chua, Yanhao Wang, Teodora Baluta, Prateek Saxena 等NDSS 2019 · 被引用 40 次
- AirTaint: Making Dynamic Taint Analysis Faster and EasierQian Sang, Yanhao Wang, Yuwei Liu, Xiangkun Jia 等S&P 2024 · 被引用 11 次
- HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware TracingYiyu Zhang, Tianyi Liu, Yueyang Wang, Yun Qi 等OOPSLA 2024 · 被引用 7 次
- Ninja: Towards Transparent Tracing and Debugging on ARMZhenyu Ning, Fengwei ZhangUSENIX Security 2017 · 被引用 62 次
- SymQEMU: Compilation-based symbolic execution for binariesSebastian Poeplau, Aurélien FrancillonNDSS 2021
