Proceedings of the Institute for System Programming of the RAS
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Proceedings of ISP RAS:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Proceedings of the Institute for System Programming of the RAS, 2016, Volume 28, Issue 6, Pages 11–26
DOI: https://doi.org/10.15514/ISPRAS-2016-28(6)-1
(Mi tisp81)
 

This article is cited in 1 scientific paper (total in 1 paper)

On some limitations of information flow tracking in full-system emulators

M. A. Klimushenkovaa, M. G. Bakulinb, V. A. Padaryanbc, P. M. Dovgalyuka, N. I. Fursovaa, I. A. Vasilieva

a Novgorod State University
b Institute for System Programming of the Russian Academy of Sciences
c Lomonosov Moscow State University
Full-text PDF (842 kB) Citations (1)
References:
Abstract: Tracking and verification of data flows includes set of techniques that can be applied to make applications more secure, to perform software analysis for debugging or reverse engineering, and so on. Taint analysis is one of the techniques used to control data flows. This paper presents an approach for system-wide lightweight platform-aware taint analysis. We implemented proof-of-concept tool based on our approach for i386 platform upon the multi-platform simulator QEMU. Our approach uses instrumentation of QEMU intermediate representation of binary code and processes up to 8 taints simultaneously. Most of the taint analysis code is target-independent and may be used with other target platforms. For some platforms (i386 with Windows XP and Windows 7) we present Virtual Machine Introspection plugins for automatic file tainting. We demonstrate how our taint analysis system may be used to detect exploitation of software vulnerabilities.
Keywords: taint analysis, dynamic analysis, QEMU.
Funding agency Grant number
Russian Foundation for Basic Research 16-29-09632
Bibliographic databases:
Document Type: Article
Language: Russian
Citation: M. A. Klimushenkova, M. G. Bakulin, V. A. Padaryan, P. M. Dovgalyuk, N. I. Fursova, I. A. Vasiliev, “On some limitations of information flow tracking in full-system emulators”, Proceedings of ISP RAS, 28:6 (2016), 11–26
Citation in format AMSBIB
\Bibitem{KliBakPad16}
\by M.~A.~Klimushenkova, M.~G.~Bakulin, V.~A.~Padaryan, P.~M.~Dovgalyuk, N.~I.~Fursova, I.~A.~Vasiliev
\paper On some limitations of information flow tracking in full-system emulators
\jour Proceedings of ISP RAS
\yr 2016
\vol 28
\issue 6
\pages 11--26
\mathnet{http://mi.mathnet.ru/tisp81}
\crossref{https://doi.org/10.15514/ISPRAS-2016-28(6)-1}
\elib{https://elibrary.ru/item.asp?id=27679165}
Linking options:
  • https://www.mathnet.ru/eng/tisp81
  • https://www.mathnet.ru/eng/tisp/v28/i6/p11
  • This publication is cited in the following 1 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Proceedings of the Institute for System Programming of the RAS
    Statistics & downloads:
    Abstract page:145
    Full-text PDF :41
    References:26
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024