Testing Static Taint Analyzers with Equivalence Modulo Taint
Maria Christakis, Anastasia Isychev, Samuel Pilz, Florian Tesarek, Valentin Wüstholz
摘要
Static taint analyzers are widely used to detect security vulnerabilities, yet their complexity makes them prone to soundness and precision issues. Validating these analyzers is challenging because ground-truth taint flows are rarely available and differential testing requires multiple comparable tools. To address this challenge, we introduce Equivalence Modulo Taint (EMT), a testing oracle for static taint analysis that defines program equivalence in terms of preserved source-sink flows rather than program semantics. EMT enables testing a single analyzer without ground-truth labels by checking consistency of reported flows across equivalentmodulo-taint program variants. Based on EMT, we present TaintCC, a framework that generates equivalentmodulo-taint variants through semantically equivalent, taint-oblivious, and taint-aware transformations targeting recurring difficulty dimensions in taint analysis. We evaluate TaintCC on four widely used analyzers-FlowDroid, Mariana Trench, Pysa, and Semgrep-and uncover 16 unique developer-confirmed issues, showing that even mature analyzers, whether academic or industrial, remain susceptible to reliability issues.
CCS Concepts: • Software and its engineering → Software testing and debugging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- Validating SMT solvers via semantic fusionDominik Winterer, Chengyu Zhang, Zhendong SuPLDI 2020 · 被引用 80 次
- On the unusual effectiveness of type-aware operator mutations for testing SMT solversDominik Winterer, Chengyu Zhang, Zhendong SuOOPSLA 2020 · 被引用 55 次
- GrayC: Greybox Fuzzing of Compilers and Analysers for CKarine Even-Mendoza, Arindam Sharma, Alastair F. Donaldson, Cristian CadarISSTA 2023 · 被引用 52 次
- Detecting critical bugs in SMT solvers using blackbox mutational fuzzingMuhammad Numair Mansur, Maria Christakis, Valentin Wüstholz, Fuyuan ZhangFSE 2020 · 被引用 51 次
- Discovering Flaws in Security-Focused Static Analysis Tools for Android using Systematic MutationRichard Bonett, Kaushal Kafle, Kevin Moran, Adwait Nadkarni 等USENIX Security 2018 · 被引用 35 次
相关 Paper
- TRACER: Signature-based Static Analysis for Detecting Recurring VulnerabilitiesWooseok Kang, Byoungho Son, Kihong HeoCCS 2022 · 被引用 23 次
- The impact of tool configuration spaces on the evaluation of configurable taint analysis for AndroidAustin Mordahl, Shiyi WeiISSTA 2021 · 被引用 13 次
- ECSTATIC: An Extensible Framework for Testing and Debugging Configurable Static AnalysisAustin Mordahl, Zenong Zhang, Dakota Soles, Shiyi WeiICSE 2023 · 被引用 7 次
- Detecting Vulnerabilities in Linux-Based Embedded Firmware with SSE-Based On-Demand Alias AnalysisKai Cheng, Yaowen Zheng, Tao Liu, Le Guan 等ISSTA 2023 · 被引用 28 次
- WhyFlow: Interrogative Debugger for Sensemaking Taint AnalysisBurak Yetistiren, Hong Jin Kang, Miryung KimICSE 2026
