• DocumentCode
    2549491
  • Title

    DTAD: A Dynamic Taint Analysis Detector for Information Security

  • Author

    Bai, Zhiwen ; Wang, Liming ; Chen, Jinglin ; Xu, Lin ; Liu, Jian ; Liu, Xiyang

  • Author_Institution
    Software Eng. Inst., Xidian Univ., Xi´´an
  • fYear
    2008
  • fDate
    20-22 July 2008
  • Firstpage
    591
  • Lastpage
    597
  • Abstract
    Information infection and information leakage in computer systems are mainly caused by insecure network access. Considering the particularity of network security, a tool DTAD (dynamic taint analysis detector) for information flow security detection is designed and implemented, aiming at the problem of data security in network access. This tool performs log recording and state controlling for malicious access and virus vulnerability using the state-control characteristic of virtual machines. Defense systems capture network data by executing applications to determine whether these accesses (i.e. target jumping, function address and instruction access) are legitimate or not. Once an attack is detected, the tool records states of the virtual machine at the process level as well as the kernel level. For attacks caused by malicious code, the tool injects its own diagnostic code into the process space of running programs to substitute the malicious code, as a result, related information for the attacked process is collected. The tool is able to generate precise signatures for network intrusion detection by associating and comparing network data recorded in log files with process information collected by the virtual machine, the whole process is finished automatically. The tool can also precisely identify attack types and provide effective protection measures through fast signature releasing. Experiments have validated the efficiency of the tool in attack recognition and information protection, and indicated that this detection and protection system is effective in recognizing, tracking and processing taint data.
  • Keywords
    computer viruses; program diagnostics; virtual machines; attack recognition; computer systems; data security; defense systems; diagnostic code; dynamic taint analysis detector; information flow security detection; information infection; information leakage; information protection; information security; log recording; malicious access; network access; network intrusion detection; state control; virtual machines; virus vulnerability; Costs; Data security; Detectors; Information analysis; Information management; Information security; Intrusion detection; Protection; Virtual machining; Viruses (medical);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web-Age Information Management, 2008. WAIM '08. The Ninth International Conference on
  • Conference_Location
    Zhangjiajie Hunan
  • Print_ISBN
    978-0-7695-3185-4
  • Electronic_ISBN
    978-0-7695-3185-4
  • Type

    conf

  • DOI
    10.1109/WAIM.2008.60
  • Filename
    4597071