Proj CDeepFuzz Paper Reading: POLYCRUISE: A Cross-Language Dynamic Information Flow Analysis
Abstract
本文: PolyCruise
Method:
- 跨编程语言的holistic dynamic information flow analysis(DIFA)
- use a light language-specific analysis和language-agnostic online dataflow analysis来计算symbolic dependencies
实验:
数据集:PolyBench,包含小中大三种等级的benchmarks
效果:
- found 14 vulnerability, 11 confirmed, 8CVEs, 8fixed