TY - GEN
T1 - Bit-level taint analysis
AU - Yadegari, Babak
AU - Debray, Saumya
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2014/12/4
Y1 - 2014/12/4
N2 - Taint analysis has a wide variety of applications in software analysis, making the precision of taint analysis an important consideration. Current taint analysis algorithms, including previous work on bit-precise taint analyses, suffer from shortcomings that can lead to significant loss of precision (under/over tainting) in some situations. This paper discusses these limitations of existing taint analysis algorithms, shows how they can lead to imprecise taint propagation, and proposes a generalization of current bit-level taint analysis techniques to address these problems and improve their precision. Experiments using a deobfuscation tool indicate that our enhanced taint analysis algorithm leads to significant improvements in the quality of deobfuscation.
AB - Taint analysis has a wide variety of applications in software analysis, making the precision of taint analysis an important consideration. Current taint analysis algorithms, including previous work on bit-precise taint analyses, suffer from shortcomings that can lead to significant loss of precision (under/over tainting) in some situations. This paper discusses these limitations of existing taint analysis algorithms, shows how they can lead to imprecise taint propagation, and proposes a generalization of current bit-level taint analysis techniques to address these problems and improve their precision. Experiments using a deobfuscation tool indicate that our enhanced taint analysis algorithm leads to significant improvements in the quality of deobfuscation.
KW - Program Understanding
KW - Reverse Engineering
KW - Taint Analysis
UR - http://www.scopus.com/inward/record.url?scp=84924874077&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84924874077&partnerID=8YFLogxK
U2 - 10.1109/SCAM.2014.43
DO - 10.1109/SCAM.2014.43
M3 - Conference contribution
AN - SCOPUS:84924874077
T3 - Proceedings - 2014 14th IEEE International Working Conference on Source Code Analysis and Manipulation, SCAM 2014
SP - 255
EP - 264
BT - Proceedings - 2014 14th IEEE International Working Conference on Source Code Analysis and Manipulation, SCAM 2014
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 14th IEEE International Working Conference on Source Code Analysis and Manipulation, SCAM 2014
Y2 - 28 September 2014 through 29 September 2014
ER -