SAILS: static analysis of information leakage with sample

  • Authors:
  • Matteo Zanioli;Pietro Ferrara;Agostino Cortesi

  • Affiliations:
  • Università Ca' Foscari, Venice, Italy École Normale Supérieure, Paris, France;ETH, Zurich, Switzerland;Università Ca' Foscari, Venice, Italy

  • Venue:
  • Proceedings of the 27th Annual ACM Symposium on Applied Computing
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we introduce Sails, a new tool that combines Sample, a generic static analyzer, and a sophisticated domain for leakage analysis. This tool does not require to modify the original language, since it works with mainstream languages like Java, and it does not require any manual annotation. Sails can combine the information leakage analysis with different heap abstractions, inferring information leakage over programs dealing with complex data structures. We applied Sails to the analysis of the SecuriBench-micro suite. The experimental results show the effectiveness of our approach.