Skip to main navigation Skip to search Skip to main content

On the limits of information flow techniques for malware analysis and containment

  • Lorenzo Cavallaro
  • , Prateek Saxena
  • , R. Sekar
  • University of Milan
  • University of California at Berkeley

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

74 Scopus citations

Abstract

Taint-tracking is emerging as a general technique in software security to complement virtualization and static analysis. It has been applied for accurate detection of a wide range of attacks on benign software, as well as in malware defense. Although it is quite robust for tackling the former problem, application of taint analysis to untrusted (and potentially malicious) software is riddled with several difficulties that lead to gaping holes in defense. These holes arise not only due to the limitations of information flow analysis techniques, but also the nature of today's software architectures and distribution models. This paper highlights these problems using an array of simple but powerful evasion techniques that can easily defeat taint-tracking defenses. Given today's binary-based software distribution and deployment models, our results suggest that information flow techniques will be of limited use against future malware that has been designed with the intent of evading these defenses.

Original languageEnglish
Title of host publicationDetection of Intrusions and Malware, and Vulnerability Assessment - 5th International Conference, DIMVA 2008, Proceedings
Pages143-163
Number of pages21
DOIs
StatePublished - 2008
Event5th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2008 - Paris, France
Duration: Jul 10 2008Jul 11 2008

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5137 LNCS

Conference

Conference5th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2008
Country/TerritoryFrance
CityParis
Period07/10/0807/11/08

Fingerprint

Dive into the research topics of 'On the limits of information flow techniques for malware analysis and containment'. Together they form a unique fingerprint.

Cite this