作者
Wei Lin, Lu Zhang, Haotian Zhang, Kailai Shao, Mingming Zhang, Tao Xie
发表日期
2022/10/31
研讨会论文
2022 IEEE 33rd International Symposium on Software Reliability Engineering (ISSRE)
页码范围
1-12
出版商
IEEE
简介
To address software engineering tasks such as se-curity risk assessment, software change government, and access control in database applications, taint analysis approaches for SQL statements have been commonly adopted for tracking information flows in these applications. However, existing taint analysis approaches cannot track implicit flows (i.e., control dependencies between sources and sinks) for SQL statements, facing the challenges of native/unmanaged code and database management system (DBMS) complexity. To address these chal-lenges, in this paper, we propose TaintSQL, a cell-level dynamic taint analysis (DTA) framework (maintaining a taint tag for each table cell) to track fine-grained implicit flows for SQL statements. Our TaintSQL framework includes two novel techniques, namely MutaIF and MockIF. MutaIF aims to track implicit flows with causal relationships, whereas MockIF aims to …
学术搜索中的文章
W Lin, L Zhang, H Zhang, K Shao, M Zhang, T Xie - 2022 IEEE 33rd International Symposium on Software …, 2022