loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
21st Annual Computer Security Applications Conference (ACSAC'05)
Dynamic Taint Propagation for Java
Tucson, Arizona
December 05-December 09
ISBN: 0-7695-2461-3
Vivek Haldar, University of California, Irvine, CA
Deepak Chandra, University of California, Irvine, CA
Michael Franz, University of California, Irvine, CA
Improperly validated user input is the underlying root cause for a wide variety of attacks on web-based applications. Static approaches for detecting this problem help at the time of development, but require source code and report a number of false positives. Hence, they are of little use for securing fully deployed and rapidly evolving applications. We propose a dynamic solution that tags and tracks user input at runtime and prevents its improper use to maliciously afSect the execution of the program. Our implementation can be transparently applied to Java class files, and does not require source code. Benchmarks show that the overhead of this runtime enforcement is negligible and can prevent a number of attacks.
Citation:
Vivek Haldar, Deepak Chandra, Michael Franz, "Dynamic Taint Propagation for Java," acsac, pp.303-311, 21st Annual Computer Security Applications Conference (ACSAC'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.