Sensitive data tracking using dynamic taint analysis
    2.
    发明授权
    Sensitive data tracking using dynamic taint analysis 有权
    使用动态色调分析的敏感数据跟踪

    公开(公告)号:US08893280B2

    公开(公告)日:2014-11-18

    申请号:US12638377

    申请日:2009-12-15

    申请人: Jaeyeon Jung Yu Zhu

    发明人: Jaeyeon Jung Yu Zhu

    IPC分类号: G06F21/00

    摘要: A system and method for tracking sensitive data uses dynamic taint analysis to track sensitive data as the data flows through a target application running on a computer system. In general, the system and method for tracking sensitive data marks data as tainted when the data input to the target application is indicated as sensitive. The system and method may then track the propagation of the tainted data as the data is read from and written to memory by the target application to detect if the tainted data is output from the application (e.g., leaked). Dynamic binary translation may be used to provide binary instrumentation of the target application for dynamic taint analysis to track propagation of the tainted data at the instruction level and/or the function level. Of course, many alternatives, variations, and modifications are possible without departing from this embodiment.

    摘要翻译: 用于跟踪敏感数据的系统和方法使用动态污点分析来跟踪敏感数据,因为数据流经计算机系统上运行的目标应用程序。 通常,用于跟踪敏感数据的系统和方法将数据标记为当输入到目标应用的数据被指示为敏感时被污染。 然后,系统和方法可以跟踪被污染数据的传播,因为目标应用程序从数据读取和写入存储器,以检测污染的数据是否从应用程序输出(例如泄漏的)。 可以使用动态二进制翻译来提供用于动态污点分析的目标应用的二元检测,以跟踪在指令级和/或功能级别处的污染数据的传播。 当然,在不偏离本实施例的情况下,可以进行许多替代,变化和修改。

    SENSITIVE DATA TRACKING USING DYNAMIC TAINT ANALYSIS
    3.
    发明申请
    SENSITIVE DATA TRACKING USING DYNAMIC TAINT ANALYSIS 有权
    敏感数据跟踪使用动态分析

    公开(公告)号:US20110145918A1

    公开(公告)日:2011-06-16

    申请号:US12638377

    申请日:2009-12-15

    申请人: Jaeyeon Jung Yu Zhu

    发明人: Jaeyeon Jung Yu Zhu

    IPC分类号: G06F11/00

    摘要: A system and method for tracking sensitive data uses dynamic taint analysis to track sensitive data as the data flows through a target application running on a computer system. In general, the system and method for tracking sensitive data marks data as tainted when the data input to the target application is indicated as sensitive. The system and method may then track the propagation of the tainted data as the data is read from and written to memory by the target application to detect if the tainted data is output from the application (e.g., leaked). Dynamic binary translation may be used to provide binary instrumentation of the target application for dynamic taint analysis to track propagation of the tainted data at the instruction level and/or the function level. Of course, many alternatives, variations, and modifications are possible without departing from this embodiment.

    摘要翻译: 用于跟踪敏感数据的系统和方法使用动态污点分析来跟踪敏感数据,因为数据流经计算机系统上运行的目标应用程序。 通常,用于跟踪敏感数据的系统和方法将数据标记为当输入到目标应用的数据被指示为敏感时被污染。 然后,系统和方法可以跟踪被污染数据的传播,因为目标应用程序从数据读取和写入存储器,以检测污染的数据是否从应用程序输出(例如泄漏的)。 可以使用动态二进制翻译来提供用于动态污点分析的目标应用的二元检测,以跟踪在指令级和/或功能级别处的污染数据的传播。 当然,在不偏离本实施例的情况下,可以进行许多替代,变化和修改。