Oracle Corporation
Staged dynamic taint flow inference
Last updated:
Abstract:
A method may include obtaining, from a runtime system that executes code, a source value at a source point of the code and a sink value at a sink point of the code, identifying a potential taint flow from the source point to the sink point by performing a series of taint inferences that each infer a relationship between the source value and the sink value, and determining whether the potential taint flow is an actual taint flow by performing a series of taint checks that each analyze the execution of the code using the source value and the sink value.
Status:
Grant
Type:
Utility
Filling date:
8 Aug 2018
Issue date:
9 Feb 2021