Static program analysis assisted dynamic taint tracking for software vulnerability discovery

Ruoyu Zhang,Shiqiu Huang,Zhengwei Qi,Haibing Guan
DOI: https://doi.org/10.1016/j.camwa.2011.08.001
IF: 3.218
2012-01-01
Computers & Mathematics with Applications
Abstract:The evolution of computer science has exposed us to the growing gravity of security problems and threats. Dynamic taint analysis is a prevalent approach to protect a program from malicious behaviors, but fails to provide any information about the code which is not executed. This paper describes a novel approach to overcome the limitation of traditional dynamic taint analysis by integrating static analysis into the system and presents framework SDCF to detect software vulnerabilities with high code coverage. Our experiments show that SDCF is not only able to provide efficient runtime protection by introducing an overhead of 4.16× based on the taint tracing technique, but is also capable of discovering latent software vulnerabilities which have not been exploited, and achieve code coverage of more than 90%.
What problem does this paper attempt to address?