Panalyst: privacy-aware remote error analysis on commodity software
Rui Wang, Xiaofeng Wang, Zhuowei Li · 2008
Remote error analysis aims at timely detection and rem-edy of software vulnerabilities through analyzing run-time errors that occur on the client. This objective can only be achieved by offering users effective protection of their private information and minimizing the perfor-mance impact of the analysis on their systems without undermining the amount of information the server can access for understanding errors. To this end, we propose in the paper a new technique for privacy-aware remote analysis, called Panalyst. Panalyst includes a client com-ponent and a server component. Once a runtime excep-tion happens to an application, Panalyst client sends the server an initial error report that includes only public in-formation regarding the error, such as the length of the packet that triggers the exception. Using an input built from the report, Panalyst server performs a taint analysis and symbolic execution on the application, and adjusts the input by querying the client about the information upon which the execution of the application depends. The client agrees to answer only when the reply does not give away too much user information. In this way, an input that reproduces the error can be gradually built on the server under the client’s consent. Our experimen-tal study of this technique demonstrates that it exposes a very small amount of user information, introduces neg-ligible overheads to the client and enables the server to effectively analyze an error. 1