arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Mystra:通过影子虚拟机进行声明式动态污点分析

Mystra: Declarative Dynamic Taint Analysis via Shadow Virtual Machine

Zhuohao Zhang, Junkun Liu, Rui Yang, Yinzhi Cao, Ziyang Li

arXiv 2607.12308首次发表:更新:

AI 中文总结

研究针对解释型语言的动态污点分析问题,核心方法是引入影子虚拟机并设计声明式污点规范语言Mystra,主要贡献是实现工具Shar,在准确性和性能上均有出色表现,如V8实例召回率高且零误报,运行时开销低。

AI 中文摘要

对于像JavaScript和Python这样的解释型语言,动态污点分析(DTA)需要具备观察宿主运行时操作、维护并行污点状态以及定义污点传播方式这三种能力。现有系统将这些能力耦合在一个检测机制中,会带来高运行时开销或需要特定引擎嵌入。本文开发了一个可扩展、高效且准确的DTA引擎。引入影子虚拟机来跟踪多级污点、来源和跨调用上下文,设计了声明式污点规范语言Mystra,具有形式化操作语义,能友好适配语言模型,有验证器辅助规则合成,能声明式表达高阶函数污点转移,规则提前编译为二进制并在常量运行时调度。实现了工具Shar,在不同运行时进行实例化。在准确性方面,V8实例在特定测试中召回率达95.5%且零误报;在性能方面,Shar运行时开销在特定基准测试中仅为1.85倍,比NodeMedic - FINE低22.7倍,同时在支持类别中召回率高33.2%。

英文摘要

Dynamic taint analysis (DTA) for interpreted languages like JavaScript and Python requires three capabilities: observing host-runtime operations, maintaining parallel taint states, and defining how taint propagates. Existing systems couple these capabilities within an instrumentation mechanism -- source-rewriting or engine-native -- either incurring high runtime overhead or demanding engine-specific embeddings. There is yet to be a runtime-independent abstraction of a general DTA that separates taint semantics and state transitions from how a host runtime executes them. We set out to develop a DTA engine that is extensible, performant, and accurate. To achieve this, we introduce a Shadow Virtual Machine executing alongside host runtimes that tracks multi-level taint, provenance, and cross-invocation context. We design Mystra, a declarative taint specification language with formal operational semantics. Mystra is designed to be language model friendly, and is equipped with validators enabling trustworthy automated synthesis of rules. Mystra is also the first to express higher-order function taint transfer declaratively. Further, Mystra rules are compiled ahead of time to a binary representation and dispatch in constant runtime. We implement our vision into a tool named Shar, which contains a shared core engine and instantiations on three runtimes: V8 in both Node$.$js and Chromium (embedding), SpiderMonkey (engine), and CPython (language). Accuracy wise, on SecBench$.$js (493 in-scope CVEs across four CWE categories), our V8 instantiation achieves 95.5% recall with zero false positives on patched-version testing. Regarding performance, the runtime overhead of Shar is 1.85$\times$ over vanilla Node$.$js on NodeMedic's benchmarks, and is 22.7$\times$ lower than NodeMedic-FINE on identical workloads, all the while producing 33.2% higher recall in its supported categories.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑