Compositional Taint Analysis for Enforcing Security Policies at Scale
Abstract
Automated static dataflow analysis is an effective technique for detecting security critical issues like sensitive data leak, and vulnerability to injection attacks. Ensuring high precision and recall requires an analysis that is context, field and object sensitive. However, it is challenging to attain high precision and recall and scale to large industrial code bases. Compositional style analyses in which individual software components are analyzed separately, independent from their usage contexts, compute reusable summaries of components. This is an essential feature when deploying such analyses in CI/CD at code-review time or when scanning deployed container images. In both these settings the majority of software components stay the same between subsequent scans. However, it is not obvious how to extend such analyses to check the kind of contextual taint specifications that arise in practice, while maintaining compositionality.
BibTeX
@inproceedings{Banerjee-al:FSE23,
author = {Subarno Banerjee and
Siwei Cui and
Michael Emmi and
Antonio Filieri and
Liana Hadarean and
Peixuan Li and
Linghui Luo and
Goran Piskachev and
Nicol{\'{a}}s Rosner and
Aritra Sengupta and
Omer Tripp and
Jingbo Wang},
title = {Compositional Taint Analysis for Enforcing Security Policies at Scale},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {1985--1996},
publisher = {{ACM}},
year = {2023},
}