Despite significant advances, static vulnerability analysis suffers from three critical limitations: coarse sanitization modeling, which treats validation as a binary barrier; database blindness, which breaks taint tracking across persistence layers; and shallow object-oriented analysis, which misses field-level and interprocedural data flows. These flaws stem from a common root cause: Code Property Graph (CPG)-based taint analyses lack a compositional semantic layer to jointly model sanitization, persistence, and object aliasing. Consequently, existing tools generate excessive false positives or miss critical attack paths entirely. To address these limitations, we present TaintRadar, an approach that systematically augments CPGs with three semantic analysis layers. First, vulnerability-typed sanitization computes node-level safety guarantees using transfer functions and context-sensitive parameter binding. Second, persistence-aware propagation integrates database schema constraints and query safety analysis to track multi-script attack paths traversing shared database states. Finally, object-aware reaching definitions combine calling and bounded variable alias contexts to precisely model object-field mutations across method boundaries. We evaluate TaintRadar on both synthetic benchmarks and real-world systems. On the SARD benchmark, TaintRadar drastically reduces false positives while maintaining 80% overall accuracy. Deployed across 19 real-world PHP applications, it rediscovered the majority of known CVEs and uncovered 29 confirmed zero-day vulnerabilities, including 26 SQL injection and 3 stored XSS vulnerabilities, that have already received CVE identifiers. These results demonstrate that semantic-aware graph augmentation significantly improves the precision, coverage, and practical utility of static taint analysis.


翻译:暂无翻译

0
下载
关闭预览

相关内容

Stabilizing Transformers for Reinforcement Learning
专知会员服务
61+阅读 · 2019年10月17日
disentangled-representation-papers
CreateAMind
26+阅读 · 2018年9月12日
用 LDA 和 LSA 两种方法来降维和做 Topic 建模
AI研习社
13+阅读 · 2018年8月24日
论文浅尝 | 知识图谱问答中的层次类型约束主题实体识别
语义分割+视频分割开源代码集合
极市平台
35+阅读 · 2018年3月5日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
VIP会员
相关主题
最新内容
《最强大的军事网状网络》
专知会员服务
6+阅读 · 9月7日
《预测陆军征兵任务分配》110页
专知会员服务
5+阅读 · 9月7日
分层反无人机系统发展新趋势
专知会员服务
11+阅读 · 9月3日
何为协作武器?
专知会员服务
11+阅读 · 9月1日
相关VIP内容
Stabilizing Transformers for Reinforcement Learning
专知会员服务
61+阅读 · 2019年10月17日
相关基金
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员