TaintStream: fine-grained taint tracking for big data platforms through dynamic code translation
Chengxu Yang, Yuanchun Li, Mengwei Xu, Zhenpeng Chen, Yunxin Liu, Gang Huang, Xuanzhe Liu
摘要
Big data has become valuable property for enterprises and enabled various intelligent applications. Today, it is common to host data in big data platforms (e.g., Spark), where developers can submit scripts to process the original and intermediate data tables. Meanwhile, it is highly desirable to manage the data to comply with various privacy requirements. To enable flexible and automated privacy policy enforcement, we propose TaintStream, a fine-grained taint tracking framework for Spark-like big data platforms. TaintStream works by automatically injecting taint tracking logic into the data processing scripts, and the injected scripts are dynamically translated to maintain a taint tag for each cell during execution. The dynamic translation rules are carefully designed to guarantee noninterference in the original data operation. By defining different semantics of taint tags, TaintStream can enable various data management applications such as access control, data retention, and user data erasure. Our experiments on a self-crafted benchmark suite show that TaintStream is able to achieve accurate cell-level taint tracking with a precision of 93.0% and less than 15% overhead. We also demonstrate the usefulness of TaintStream through several real-world use cases of privacy policy enforcement. * This work was done while Chengxu Yang, Mengwei Xu, and Yunxin Liu were working at Microsoft (as an intern, visiting scholar, and researcher, respectively). † Chengxu Yang and Yuanchun Li contributed equally. ‡ Correspondence goes to Yuanchun Li and Xuanzhe Liu.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware TracingYiyu Zhang, Tianyi Liu, Yueyang Wang, Yun Qi 等OOPSLA 2024 · 被引用 7 次
- NaturalFuzz: Natural Input Generation for Big Data AnalyticsAhmad Humayun, Yaoxuan Wu, Miryung Kim, Muhammad Ali GulzarASE 2023 · 被引用 2 次
- Co-dependence Aware Fuzzing for Dataflow-Based Big Data AnalyticsAhmad Humayun, Miryung Kim, Muhammad Ali GulzarFSE 2023 · 被引用 2 次
- DeSQL: Interactive Debugging of SQL in Data-Intensive Scalable ComputingSabaat Haroon, Chris Brown, Muhammad Ali GulzarFSE 2024 · 被引用 2 次
它引用的顶会 Paper2
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 被引用 188 次
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen 等CCS 2018 · 被引用 93 次
相关 Paper
- Secure Data Analytics in Apache Spark with Fine-grained Policy Enforcement and Isolated ExecutionByeongwook Kim, Jaewon Hur, Adil Ahmad, Byoungyoung LeeNDSS 2025
- Splice: Efficiently Removing a User's Data from In-memory Application StateXueyuan Han, James Mickens, Siddhartha SenCCS 2023
- Zeph: Cryptographic Enforcement of End-to-End Data PrivacyLukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh 等OSDI 2021 · 被引用 35 次
- FSAFlow: Lightweight and Fast Dynamic Path Tracking and Control for Privacy Protection on Android Using Hybrid Analysis with State-Reduction StrategyZhi Yang, Zhanhui Yuan, Shuyuan Jin, Xingyuan Chen 等S&P 2022 · 被引用 11 次
- FLARE: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework (Flavor: Systems)Xiang Li, Fabing Li, Mingyu GaoVLDB 2023 · 被引用 14 次
