V2EX taint-analysis

Taint Analysis

定义 Definition

Taint analysis(污点分析/污染分析)是一种用于跟踪“不可信数据”(如用户输入、网络数据、外部文件)在程序中如何流动与传播的分析方法,用来判断这些数据是否会到达敏感位置并造成风险(例如 SQL 注入、命令注入、XSS),以及是否在途中经过了正确的清理/校验(sanitization)。在安全领域和程序分析领域非常常见。

发音 Pronunciation (IPA)

/tent nlss/

例句 Examples

User input is marked as tainted during taint analysis.
在污点分析中,用户输入会被标记为“被污染”的数据。

The security team used taint analysis to trace how a URL parameter reached a database query without proper sanitization.
安全团队使用污点分析来追踪某个 URL 参数如何在未正确清理的情况下进入数据库查询语句。

词源 Etymology

taint 原意为“弄脏、玷污”,来自中古英语 teinten(与“染色/污染”的含义相关);在计算机安全语境中借用为“被不可信来源污染的数据”。analysis 来自希腊语 analyein,意为“分解、解析”。合在一起,taint analysis 就是“对被污染(不可信)数据的传播路径进行解析与追踪”。

相关词 Related Words

文学与著作中的用例 Literary Works

  • TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones(Enck 等,2010)经典移动端动态污点跟踪工作
  • FlowDroid: Precise Context, Flow, Field, Object-sensitive and Lifecycle-aware Taint Analysis for Android Apps(Arzt 等,2014)Android 静态污点分析代表性论文
  • The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities(Dowd, McDonald, Schuh)讨论多种漏洞分析方法,常涉及不可信数据流的追踪思想
  • Secure Programming with Static Analysis(Chess, West)静态分析实践中常涵盖污点/数据流相关概念
关于     帮助文档     自助推广系统     博客     API     FAQ     Solana     1819 人在线   最高记录 6679       Select Language
创意工作者们的社区
World is powered by solitude
VERSION: 3.9.8.5 7ms UTC 05:37 PVG 13:37 LAX 21:37 JFK 00:37
Do have faith in what you're doing.
ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86