Offline taint prediction for multi-threaded applications.
Emmanuel Sifakis, Laurent Mounier · 2013
Dynamic analysis of multi-threaded applications running on parallel architectures is notoriously a challenging issue. In this work we consider taint analysis as a typical information flow property. The approach we propose extends properties collected at runtime on a single parallel execution σ ∥ to a set of execution sequences corresponding to plausible serializations of σ ∥. Taint values are inferred using a slidingwindow based static analysis, performed on a fragment of an execution trace. We provide sufficient conditions to reduce some of the false positives produced by the over-approximation of serializations. Only explicit taint propagation is captured but special care has been taken to handle lock-based critical sections correctly. A proofof-concept implementation has been developed using the CETUS framework, and some experimental results are given. Finally, the framework could be extended to perform other types of information flow analysis.