透過您的圖書館登入
IP:3.147.42.168
  • 期刊
  • OpenAccess

SWIFT: Decoupled System-Wide Information Flow Tracking and its Optimizations

並列摘要


Information flow analysis is a widely-adopted technique in software testing and malware analysis. For information flow analysis, a system-level emulator equipped with dynamic information flow tracking capability, DIFT, is needed. However, its effectiveness comes at a price of severe performance degradation due to interleaved system emulation and DIFT analysis. In this paper, a decoupled system-wide information flow tracking scheme, SWIFT, is proposed. Through decoupling system-wide information flow tracking from emulation, SWIFT regains the memory locality and code optimization. The proposed methods are able to aggressively eliminate dependency between the system-level emulator and the analysis thread. Our performance evaluation indicates that, under the same hardware specifications, SWIFT runs 2.74~7.48 times faster than the conventional interleaved design while being benchmarked by PassMark Performance Test 6.0. The performance improvement consequently makes the online analysis feasible in practice.

被引用紀錄


Su, H. T. (2011). 藉系統層的資訊流動追蹤以偵測Android平台上竊取敏感資料的行為 [master's thesis, National Chiao Tung University]. Airiti Library. https://doi.org/10.6842/NCTU.2011.00956
劉芳瑜(2011)。基於內核函數呼叫模式之惡意程式種類辨認方法〔碩士論文,國立交通大學〕。華藝線上圖書館。https://doi.org/10.6842/NCTU.2011.00950

延伸閱讀