Date & Time
Wednesday, April 15, 2026, 4:15 PM - 4:45 PM
Name
Finding Injection Vulnerabilities: Improvements of the Taint Analysis of the Clang Static Analyzer
Session Type
Technical Talk
Abstract/s
Clang Static Analyzer provides a configurable taint analysis checker optin.taint.GenericTaint and a few specialized taint checkers (in the optin.taint group) which can identify potential improper input validation security vulnerabilities. Although promising, the current implementation is still in its early stages, and its limitations prevent it from efficient industrial use. We were able to identify key issues after taking measurements on both the synthetic Juliet test suite and real-world projects. Based on these findings, we propose some improvements to the current solution, which we prototyped and evaluated.
Speakers
Location Name
Pembroke + Herbert