RISS 학술연구정보서비스

검색
다국어 입력

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

변환된 중국어를 복사하여 사용하시면 됩니다.

예시)
  • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
  • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
닫기
    인기검색어 순위 펼치기

    RISS 인기검색어

      Automated Cryptography Usage Analysis using Dynamic Taint Tracking = 동적 오염추적을 이용한 자동화된 암호 사용 분석

      한글로보기

      https://www.riss.kr/link?id=T14911020

      • 0

        상세조회
      • 0

        다운로드
      서지정보 열기
      • 내보내기
      • 내책장담기
      • 공유하기
      • 오류접수

      부가정보

      다국어 초록 (Multilingual Abstract)

      Since sensitive data (e.g., user credentials, biometric data, personal data, and digital contents) are typically used in an application, protecting such data is essential to store and manage them in a secure manner. Therefore, misuse of cryptography i...

      Since sensitive data (e.g., user credentials, biometric data, personal data, and digital contents) are typically used in an application, protecting such data is essential to store and manage them in a secure manner. Therefore, misuse of cryptography is becoming one of the most common issues in secure software development. However, it is not straightforward to analyze how sensitive data is protected well in a device.
      In this paper, we propose a novel approach to track the entire flow of all sensitive data including input data and cryptographically transformed data by only executing binary using dynamic taint analysis.
      We have developed a prototype system called CRAY (Crypto-RAY) and demonstrated that CRAY can analyze entire cryptography usages in runtime and detect four types of cryptographic misuses (e.g., Weak algorithm and weak option, Hardcoded key and IV, Insufficient iteration in PBKDF, and Leak without encryption). We also propose a method called tag-merge trace to solve the multi-tag limitation of the existing taint analysis. The performance experiment shows that CRAY can use a large number of taint tags to track a plenty of input data (e.g. binary image, file, socket, and stdin) without any significant runtime overhead, while the state-of-the-art taint tracking tool can only use a small number of taint tags due to memory consumption and performance slowdown.

      더보기

      목차 (Table of Contents)

      • 1. Introduction 1
      • 2. Related work 4
      • 2.1. Static analysis 4
      • 2.2. Dynamic analysis 5
      • 3. Background 8
      • 1. Introduction 1
      • 2. Related work 4
      • 2.1. Static analysis 4
      • 2.2. Dynamic analysis 5
      • 3. Background 8
      • 3.1. Mistakes in cryptography usage 8
      • 3.2. Limitations in previous approaches 10
      • 4. Design 16
      • 4.1. Architecture 17
      • 4.2. Crypto API modeling 18
      • 4.3. Data tracking in runtime 21
      • 4.4. Multi-tag taint propagation 24
      • 4.5. Data flow and cryptography usage analysis 27
      • 5. Evaluation 31
      • 5.1. Cryptographic misuse analysis 32
      • 5.2. Performance 35
      • 6. Conclusions 39
      • 6.1. Limitations 39
      • 6.2. Future work 40
      • References 41
      • Korean Abstract 44
      더보기

      분석정보

      View

      상세정보조회

      0

      Usage

      원문다운로드

      0

      대출신청

      0

      복사신청

      0

      EDDS신청

      0

      동일 주제 내 활용도 TOP

      더보기

      주제

      연도별 연구동향

      연도별 활용동향

      연관논문

      연구자 네트워크맵

      공동연구자 (7)

      유사연구자 (20) 활용도상위20명

      이 자료와 함께 이용한 RISS 자료

      나만을 위한 추천자료

      해외이동버튼