Journal Article10.1016/J.COSE.2015.02.006
A practical off-line taint analysis framework and its application in reverse engineering of file format
6
TL;DR: A novel dynamic taint analysis framework that aims to extract the complete taint data flow while eliminating the bottlenecks that occur in existing tools, with applications to file-format reverse engineering and the needs of further security-related research.
read more
About: This article is published in Computers & Security. The article was published on 01 Jun 2015. The article focuses on the topics: Taint checking & File format.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
StraightTaint: decoupled offline symbolic taint analysis
Jiang Ming,Dinghao Wu,Jun Wang,Gaoyao Xiao,Peng Liu +4 more
- 25 Aug 2016
TL;DR: This paper proposes a novel technique to allow very lightweight logging, resulting in much lower execution slowdown, while still permitting us to perform full-featured offline taints analysis, and develops StraightTaint, a hybrid taint analysis tool that completely decouples the program execution and taintAnalysis.
51
BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel
Jiaye Pan,Yi Zhuang,Binglin Sun +2 more
TL;DR: This paper proposes a new lightweight analysis method for binary programs with the assistance of hardware features and the operating system kernel, named BAHK, which can automatically analyze the target program by stealth and has wide applicability.
A New Program Classification Method Based on Binary Instrumentation and Instruction Flow Feature Extraction
Baojiang Cui,Mengchen Cao,Shilei Chen,Weikong Qi +3 more
- 04 Nov 2015
TL;DR: This paper presents a new method of program classification using binary instrumentation, dynamic instruction flow feature extraction, auto feature selection and Naive Bayes classifier technology.
3
Lightweight and Efficient Hypervisor-Based Dynamic Binary Instrumentation and Analysis Method
TL;DR: This article proposes a new lightweight hypervisor-based dynamic binary instrumentation method, which uses the virtualization features of new processors to perform transparent and efficient execution interception of the target program, so that it can instrument thetarget program and redirect the original execution.
HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware Tracing
Yiyu Zhang,Tianyi Liu,Yueyang Wang,Yun Lian Qi,Kai Ji,Jian Tang,Xiaoliang Wang,Xuandong Li,Zhiqiang Zuo +8 more
TL;DR: This paper proposes HardTaint, a system that achieves production-run dynamic taint analysis with minimal runtime overhead (8%) through a hybrid approach combining static analysis, selective hardware tracing, and parallel graph processing techniques.
References
Pin: building customized program analysis tools with dynamic instrumentation
Chi-Keung Luk,Robert Cohn,Robert Muth,Harish Patil,Artur Klauser,Geoff Lowney,Steven Wallace,Vijay Janapa Reddi,Kim Hazelwood +8 more
- 12 Jun 2005
TL;DR: The goals are to provide easy-to-use, portable, transparent, and efficient instrumentation, and to illustrate Pin's versatility, two Pintools in daily use to analyze production software are described.
Valgrind: a framework for heavyweight dynamic binary instrumentation
Nicholas Nethercote,Julian Seward +1 more
- 10 Jun 2007
TL;DR: Valgrind is described, a DBI framework designed for building heavyweight DBA tools that can be used to build more interesting, heavyweight tools that are difficult or impossible to build with other DBI frameworks such as Pin and DynamoRIO.
•Proceedings Article
Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software
James Newsome,Dawn Song +1 more
- 01 Jan 2005
TL;DR: TaintCheck as mentioned in this paper performs dynamic taint analysis by performing binary rewriting at run time, which can reliably detect most types of exploits and produces no false positives for any of the many different programs that were tested.
All You Ever Wanted to Know about Dynamic Taint Analysis and Forward Symbolic Execution (but Might Have Been Afraid to Ask)
Edward J. Schwartz,Thanassis Avgerinos,David Brumley +2 more
- 16 May 2010
TL;DR: The algorithms for dynamic taint analysis and forward symbolic execution are described as extensions to the run-time semantics of a general language to highlight important implementation choices, common pitfalls, and considerations when using these techniques in a security context.
Control flow analysis
TL;DR: The basic control flow relationships are expressed in a directed graph and various graph constructs are found and shown to codify interesting global relationships.
908