Dynamic Diluted Taint Analysis for Evaluating Detected Policy Violations
Максим Геннадьевич Бакулин, Maria Anatolyevna Klimushenkova, Danila Egorov · 2017
Dynamic taint analysis is a well-known technique. This article describes some difficulties that have to be dealt with when using dynamic taint analysis with full-system emulation. A new method is proposed to evaluate the risk of a detected policy violation. The method is called Diluted Taint: each tainted byte has an assigned integer value that shows how much taint resides in this byte. High value represents fresh taint, that possesses more threat, low value means that many operations occurred with this fragment of data and it is not that dangerous. When a policy violation occurs, these values are used by an expert to quickly evaluate the potential threat and prioritize fixing dangerous ones first.