kirancodes.me
To Proof Maintenance & Beyond!

Compositional Taint Analysis for Enforcing Security Policies at Scale

Subarno Banerjee, Siwei Cui, Michael Emmi, Antonio Filieri, Liana Hadarean, Peixuan Li, Linghui Luo, Goran Piskachev, Nicolás Rosner, Aritra Sengupta, Omer Tripp, Jingbo Wang

Abstract

Automated static dataflow analysis is an effective technique for detecting security critical issues like sensitive data leak, and vulnerability to injection attacks. Ensuring high precision and recall requires an analysis that is context, field and object sensitive. However, it is challenging to attain high precision and recall and scale to large industrial code bases. Compositional style analyses in which individual software components are analyzed separately, independent from their usage contexts, compute reusable summaries of components. This is an essential feature when deploying such analyses in CI/CD at code-review time or when scanning deployed container images. In both these settings the majority of software components stay the same between subsequent scans. However, it is not obvious how to extend such analyses to check the kind of contextual taint specifications that arise in practice, while maintaining compositionality.

BibTeX
@inproceedings{Banerjee-al:FSE23,
  author    = {Subarno Banerjee and
               Siwei Cui and
               Michael Emmi and
               Antonio Filieri and
               Liana Hadarean and
               Peixuan Li and
               Linghui Luo and
               Goran Piskachev and
               Nicol{\'{a}}s Rosner and
               Aritra Sengupta and
               Omer Tripp and
               Jingbo Wang},
  title     = {Compositional Taint Analysis for Enforcing Security Policies at Scale},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {1985--1996},
  publisher = {{ACM}},
  year      = {2023},
}

Related papers