- Patent Title: Dynamic, non-invasive taint tracking using auto-generated datatypes
-
Application No.: US15862347Application Date: 2018-01-04
-
Publication No.: US10783243B2Publication Date: 2020-09-22
- Inventor: Florian Loch , Martin Johns
- Applicant: SAP SE
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Agency: Jones Day
- Main IPC: G06F21/55
- IPC: G06F21/55 ; H04L29/06 ; G06F3/06 ; G06F12/14 ; G06F21/53

Abstract:
Systems and methods are provided herein for dynamic, non-invasive taint tracking using auto-generated datatypes. A proxy entry point component of a taint-aware environment continuously monitors for a request to initiate an application. The application has an associated runtime environment and profile parameters specific to the application. Upon identifying the request, a core component of the taint-aware environment generates a set of augmented classes based on the profile parameters. The set of augmented classes contains taint-tracking functionality. The proxy entry point component modifies an initiation pathway of the application to force the runtime environment to retrieve the set of augmented classes prior to execution of the application. The runtime environment continuously monitors for tainted data or tainted code passed through or contained within the application based on the taint-tracking functionality of the set of augmented classes.
Public/Granted literature
- US20190205532A1 Dynamic, Non-Invasive Taint Tracking Using Auto-Generated Datatypes Public/Granted day:2019-07-04
Information query