Matches in SemOpenAlex for { <https://semopenalex.org/work/W4313152134> ?p ?o ?g. }
- W4313152134 abstract "To address software engineering tasks such as se-curity risk assessment, software change government, and access control in database applications, taint analysis approaches for SQL statements have been commonly adopted for tracking information flows in these applications. However, existing taint analysis approaches cannot track implicit flows (i.e., control dependencies between sources and sinks) for SQL statements, facing the challenges of native/unmanaged code and database management system (DBMS) complexity. To address these chal-lenges, in this paper, we propose TaintSQL, a cell-level dynamic taint analysis (DTA) framework (maintaining a taint tag for each table cell) to track fine-grained implicit flows for SQL statements. Our TaintSQL framework includes two novel techniques, namely MutaIF and MockIF. MutaIF aims to track implicit flows with causal relationships, whereas MockIF aims to dynamically track implicit flows at runtime. We implement the two techniques of TaintSQL and evaluate them on a set of test subjects to assess their effectiveness and efficiency. The evaluation results show that both techniques effectively track fine-grained implicit flows for SQL statements with reasonable runtime overhead. The F1 scores of MutaIF and MockIF are 96.2% and 97.9%, respectively. We also conduct an industrial study of MutaIF in an international IT company (which serves over 1 billion global users and 80 million merchants). The positive feedback from the software engineers also demonstrates the practicability of the TaintSQL framework and the MutaIF technique in industrial settings." @default.
- W4313152134 created "2023-01-06" @default.
- W4313152134 creator A5039728001 @default.
- W4313152134 creator A5044757881 @default.
- W4313152134 creator A5046887099 @default.
- W4313152134 creator A5048118068 @default.
- W4313152134 creator A5084705199 @default.
- W4313152134 creator A5089131616 @default.
- W4313152134 date "2022-10-01" @default.
- W4313152134 modified "2023-09-30" @default.
- W4313152134 title "TaintSQL: Dynamically Tracking Fine-Grained Implicit Flows for SQL Statements" @default.
- W4313152134 cites W1989790414 @default.
- W4313152134 cites W2010475118 @default.
- W4313152134 cites W2017025011 @default.
- W4313152134 cites W2040867586 @default.
- W4313152134 cites W2060692877 @default.
- W4313152134 cites W2070560901 @default.
- W4313152134 cites W2086106235 @default.
- W4313152134 cites W2089745089 @default.
- W4313152134 cites W2094716892 @default.
- W4313152134 cites W2103211721 @default.
- W4313152134 cites W2111403266 @default.
- W4313152134 cites W2118731196 @default.
- W4313152134 cites W2132204639 @default.
- W4313152134 cites W2166743230 @default.
- W4313152134 cites W2171295941 @default.
- W4313152134 cites W2533311740 @default.
- W4313152134 cites W2726256221 @default.
- W4313152134 cites W2767389543 @default.
- W4313152134 cites W2794883415 @default.
- W4313152134 cites W2890431379 @default.
- W4313152134 cites W2946864865 @default.
- W4313152134 cites W2968870490 @default.
- W4313152134 cites W2980178716 @default.
- W4313152134 cites W2987470874 @default.
- W4313152134 cites W2991316809 @default.
- W4313152134 cites W3006080964 @default.
- W4313152134 cites W3015326774 @default.
- W4313152134 cites W3095119922 @default.
- W4313152134 cites W3095615032 @default.
- W4313152134 cites W3100118001 @default.
- W4313152134 cites W3108350045 @default.
- W4313152134 cites W3114167700 @default.
- W4313152134 cites W3195440983 @default.
- W4313152134 cites W4200282997 @default.
- W4313152134 cites W2157606397 @default.
- W4313152134 cites W2407361634 @default.
- W4313152134 doi "https://doi.org/10.1109/issre55969.2022.00012" @default.
- W4313152134 hasPublicationYear "2022" @default.
- W4313152134 type Work @default.
- W4313152134 citedByCount "0" @default.
- W4313152134 crossrefType "proceedings-article" @default.
- W4313152134 hasAuthorship W4313152134A5039728001 @default.
- W4313152134 hasAuthorship W4313152134A5044757881 @default.
- W4313152134 hasAuthorship W4313152134A5046887099 @default.
- W4313152134 hasAuthorship W4313152134A5048118068 @default.
- W4313152134 hasAuthorship W4313152134A5084705199 @default.
- W4313152134 hasAuthorship W4313152134A5089131616 @default.
- W4313152134 hasConcept C111919701 @default.
- W4313152134 hasConcept C115903868 @default.
- W4313152134 hasConcept C136764020 @default.
- W4313152134 hasConcept C150451098 @default.
- W4313152134 hasConcept C154420247 @default.
- W4313152134 hasConcept C164120249 @default.
- W4313152134 hasConcept C177264268 @default.
- W4313152134 hasConcept C194222762 @default.
- W4313152134 hasConcept C199360897 @default.
- W4313152134 hasConcept C2777904410 @default.
- W4313152134 hasConcept C2779960059 @default.
- W4313152134 hasConcept C41008148 @default.
- W4313152134 hasConcept C45235069 @default.
- W4313152134 hasConcept C510870499 @default.
- W4313152134 hasConcept C63116202 @default.
- W4313152134 hasConcept C77088390 @default.
- W4313152134 hasConcept C89992363 @default.
- W4313152134 hasConcept C97854310 @default.
- W4313152134 hasConceptScore W4313152134C111919701 @default.
- W4313152134 hasConceptScore W4313152134C115903868 @default.
- W4313152134 hasConceptScore W4313152134C136764020 @default.
- W4313152134 hasConceptScore W4313152134C150451098 @default.
- W4313152134 hasConceptScore W4313152134C154420247 @default.
- W4313152134 hasConceptScore W4313152134C164120249 @default.
- W4313152134 hasConceptScore W4313152134C177264268 @default.
- W4313152134 hasConceptScore W4313152134C194222762 @default.
- W4313152134 hasConceptScore W4313152134C199360897 @default.
- W4313152134 hasConceptScore W4313152134C2777904410 @default.
- W4313152134 hasConceptScore W4313152134C2779960059 @default.
- W4313152134 hasConceptScore W4313152134C41008148 @default.
- W4313152134 hasConceptScore W4313152134C45235069 @default.
- W4313152134 hasConceptScore W4313152134C510870499 @default.
- W4313152134 hasConceptScore W4313152134C63116202 @default.
- W4313152134 hasConceptScore W4313152134C77088390 @default.
- W4313152134 hasConceptScore W4313152134C89992363 @default.
- W4313152134 hasConceptScore W4313152134C97854310 @default.
- W4313152134 hasLocation W43131521341 @default.
- W4313152134 hasOpenAccess W4313152134 @default.
- W4313152134 hasPrimaryLocation W43131521341 @default.
- W4313152134 hasRelatedWork W1157955462 @default.
- W4313152134 hasRelatedWork W142115101 @default.
- W4313152134 hasRelatedWork W1538798823 @default.