Splice: Efficiently Removing a User's Data from In-memory Application State
Xueyuan Han, James Mickens, Siddhartha Sen
摘要
Splice is a new programming framework that allows security-conscious applications to efficiently locate and delete a user's in-memory state. The core technical challenge is determining how to delete a user's memory values without breaking application-specific semantic invariants involving the memory state of remaining users. Splice solves this problem using three techniques: taint tracking (which traces how a user's data flows through memory), deletion by synthesis (which overwrites each user-owned memory value in place, replacing it with a value that preserves the symbolic constraints of enclosing data structures), and a novel type system (which forces applications to employ defensive programming to avoid computing over synthesize-deleted values in unsafe ways). Using four realistic applications that we ported to Splice, we show that Splice's type system and defensive programming requirements are not onerous for developers. We also demonstrate that Splice's run-time overheads are similar to those of prior taint tracking systems, while enabling strong deletion semantics.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar 等VLDB 2020 · 被引用 82 次
- Thoth: Comprehensive Policy Compliance in Data Retrieval SystemsEslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg 等USENIX Security 2016 · 被引用 30 次
- DELF: Safeguarding deletion correctness in Online Social NetworksKatriel Cohn-Gordon, Georgios Damaskinos, Divino Neto, Joshi Cordova 等USENIX Security 2020
- Civet: An Efficient Java Partitioning Framework for Hardware EnclavesChia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey 等USENIX Security 2020
相关 Paper
- HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware TracingYiyu Zhang, Tianyi Liu, Yueyang Wang, Yun Qi 等OOPSLA 2024 · 被引用 7 次
- TaintStream: fine-grained taint tracking for big data platforms through dynamic code translationChengxu Yang, Yuanchun Li, Mengwei Xu, Zhenpeng Chen 等FSE 2021 · 被引用 11 次
- WhyFlow: Interrogative Debugger for Sensemaking Taint AnalysisBurak Yetistiren, Hong Jin Kang, Miryung KimICSE 2026
- TRust: A Compilation Framework for In-process Isolation to Protect Safe Rust against Untrusted CodeInyoung Bang, Martin Kayondo, Hyungon Moon, Yunheung PaekUSENIX Security 2023
- Extracting clean performance models from tainted programsMarcin Copik, Alexandru Calotoiu, Tobias Grosser, Nicolas Wicki 等PPoPP 2021 · 被引用 16 次
