Skip to main navigation Skip to search Skip to main content

Dynamic Taint Analysis with Label-Defined Semantics

  • Jacob Kreindl
  • , Daniele Bonetta
  • , Lukas Stadler
  • , David Leopoldseder
  • , Hanspeter Mössenböck

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

Dynamic taint analysis is a popular analysis technique which tracks the propagation of specific values while a program executes. To this end, a taint label is attached to these values and is dynamically propagated to any values derived from them. Frequent application of this analysis technique in many fields has led to the development of general-purpose analysis platforms with taint propagation capabilities. However, these platforms generally limit analysis developers to a specific implementation language, to specific propagation semantics or to specific taint label representations. In this paper we present label-defined dynamic taint analysis, a language-agnostic approach for specifying the properties of a dynamic taint analysis in terms of propagated taint labels. This approach enables analysis platforms to support arbitrary adaptations to these properties by delegating propagation decisions to propagated taint labels and thus to provide more flexibility to analysis developers than other analysis platforms. We implemented this approach in TruffleTaint, a GraalVM-based taint analysis platform, and integrated it with GraalVM's language interoperability and tooling support. We further integrated our approach with GraalVM's performance optimizations. Our performance evaluation shows that label-defined taint analysis can reach peak performance similar to that of equivalent engine-integrated taint analyses. In addition to supporting the convenient reimplementation of existing dynamic taint analyses, our approach enables new capabilities for these analyses. It also enabled us to implement a novel tooling infrastructure for analysis developers as well as tooling support for end users.
Original languageEnglish
Title of host publicationMPLR 2022
Subtitle of host publicationProceedings of the 19th International Conference on Managed Programming Languages and Runtimes
EditorsElisa Gonzalez Boix, Tobias Wrigstad
PublisherAssociation for Computing Machinery, Inc
Pages64-84
Number of pages11
ISBN (Electronic)9781450396967
DOIs
Publication statusPublished - 2022
Externally publishedYes
Event19th International Conference on Managed Programming Languages and Runtimes, MPLR 2022 - Brussels, Belgium
Duration: 14 Sept 202215 Sept 2022

Conference

Conference19th International Conference on Managed Programming Languages and Runtimes, MPLR 2022
Country/TerritoryBelgium
CityBrussels
Period14/09/2215/09/22

Funding

This research project was partially funded by Oracle Labs. We thank all members of the Virtual Machine Research Group at Oracle Labs. Oracle, Java, GraalVM, and HotSpot are trademarks or registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners. We also thank all researchers at the Johannes Kepler University’s Institute for System Software for their support of and feedback on our work.

Funders
Oracle Labs

    Fingerprint

    Dive into the research topics of 'Dynamic Taint Analysis with Label-Defined Semantics'. Together they form a unique fingerprint.

    Cite this