Generating instrumentation for data integrity of function calls
Provided are a computer program product, system, and method for generating instrumentation for data integrity of function calls. Instrumentation is generated to determine whether argument values passed to functions have changed since written to memory locations during execution of the computer program. A reference monitor that runs during execution of the computer program compares an argument value, for a function, written to a memory location to an argument value passed to the function to determine whether the argument value has changed. The reference monitor permits execution of the function with the passed argument value in response to determining that the argument value has not changed.
1 . A computer program product for implementing data flow integrity in a computer program, the computer program product comprising a computer readable storage medium having computer readable program code embodied therein that is executable to perform operations, the operations comprising:
generating instrumentation to determine whether argument values passed to function calls and system calls have changed since written to a memory during execution of the computer program;
providing a reference monitor that runs during execution of the computer program to perform:
comparing a first argument value of the argument values, for a function call, written to the memory, to a second argument value of the argument values passed to the function call, after the first argument value is received, to determine whether the second argument value has changed from the first argument value;
permitting execution of the function call with the second argument value in response to determining that the second argument value has not changed from the first argument value;
comparing a third argument value of the argument values, for a system call, written to the memory, to a fourth argument value of the argument values passed to the system call, after the third argument value is received, to determine whether the fourth argument value has changed from the third argument value; and
permitting execution of the system call with the fourth argument value in response to determining that the fourth argument value has not changed from the third argument value.
2 . The computer program product of claim 1 , wherein the reference monitor further performs during the execution of the computer program:
blocking the execution of the function call in response to determining that the second argument value has changed from the first argument value.
3 . The computer program product of claim 1 , wherein the computer program is executed in a user space, and wherein the reference monitor executes in a kernel space.
4 . The computer program product of claim 1 , wherein the operations further comprise:
generating invariants to model how operations of functions, comprising the function calls and the system calls, modify the argument values passed to the functions to generate outputs without executing the functions;
using the invariants, during the execution of the computer program, to determine whether the functions have processed the argument values passed to the functions as expected without executing the functions; and
generating an error in response to determining that an invariant of the invariants determines that one of the functions has not changed an argument value of the argument values as expected to generate the outputs.
5 . The computer program product of claim 1 , wherein the reference monitor further performs, during the execution of the computer program:
in response to determining that the second argument value passed to the function call has not changed from the first argument value, calling an invariant of the invariants for the function call to determine whether the function call has modified the second argument value as expected to generate outputs; and
continuing executing the computer program using the outputs from the function call in response to the invariant determining that the function call modified the second argument value as expected.
6 . The computer program product of claim 1 , wherein the operations further comprise:
generating a data integrity policy indicating, for a function call, an argument value of the argument values for the function call, a memory location in the memory where the argument value for the function call is written, and an invariant of the invariants for the function call to determine whether the function call modifies the argument value as expected without executing the function call; and
processing the data integrity policy to determine whether the argument value passed to the function call has changed from the argument value written to the memory location for the function call and to call the invariant for the function call to determine whether the argument value passed to the function call was modified as expected to generate output of the function call.
7 . The computer program product of claim 1 , wherein the operations further comprise:
generating a function data graph analyzing functions, comprising the function calls and the system calls, to determine how the functions modify inputs to generate outputs;
generating a call graph indicating how the functions call each other in source code of the computer program;
performing inter-procedural alias analysis to determine a set of argument values of the argument values populated through pointers;
generating a data flow graph from the function data graph, the call graph, and the inter-procedural alias analysis; and
optimizing the data flow graph to compress and coalesce redundancies in the data flow graph to simplify data flow, wherein the data flow graph is processed to determine points in the computer program at which data is received for the argument values in the functions.
8 . The computer program product of claim 1 , wherein the operations further comprise:
generating a data integrity policy indicating for the system call, the third argument value for the system call, a memory location in the memory where the third argument value received for the system call is written; and
processing, by the reference monitor, the data integrity policy to determine whether the fourth argument value passed to the system call has changed since the third argument value for the system call was written to the memory location.
9 . A system for implementing data flow integrity in a computer program, the system comprising:
a processor; and
a computer readable storage medium having computer readable program code embodied therein that when executed by the processor performs operations, the operations comprising:
generating instrumentation to determine whether argument values passed to function calls and system calls have changed since written to memory during execution of the computer program;
providing a reference monitor that runs during execution of the computer program to perform:
comparing a first argument value of the argument values, for a function call, written to the memory, to a second argument value of the argument values passed to the function call, after the first argument value is received, to determine whether the second argument value has changed from the first argument value;
permitting execution of the function call with the second argument value in response to determining that the second argument value has not changed from the first argument value;
comparing a third argument value of the argument values, for a system call, written to the memory, to a fourth argument value of the argument values passed to the system call, after the third argument value is received, to determine whether the fourth argument value has changed from the third argument value; and
permitting execution of the system call with the fourth argument value in response to determining that the fourth argument value has not changed from the third argument value.
10 . The system of claim 9 , the reference monitor further performs during the execution of the computer program:
blocking the execution of the function call in response to determining that the second argument value has changed from the first argument value.
11 . The system of claim 9 , wherein the operations further comprise:
generating invariants to model how operations of functions, comprising the function calls and the system calls, modify the argument values passed to the functions to generate outputs without executing the functions;
using the invariants, during the execution of the computer program, to determine whether the functions have processed the argument values passed to the functions as expected without executing the functions; and
generating an error in response to determining that an invariant of the invariants determines that one of the functions has not changed an argument value of the argument values as expected to generate the outputs.
12 . The system of claim 9 , wherein the reference monitor further performs, during the execution of the computer program:
in response to determining that the second argument value passed to the function call has not changed from the first argument value, calling an invariant of the invariants for the function call to determine whether the function call has modified the second argument value as expected to produce an output; and
continuing executing the computer program using the output from the function call in response to the invariant determining that the function call modified the second argument value as expected.
13 . The system of claim 9 , wherein the operations further comprise:
generating a function data graph analyzing functions, comprising the function calls and the system calls, to determine how the functions modify inputs to generate outputs;
generating a call graph indicating how the functions call each other in source code of the computer program;
performing inter-procedural alias analysis to determine a set of argument values of the argument values populated through pointers;
generating a data flow graph from the function data graph, the call graph, and the inter-procedural alias analysis; and
optimizing the data flow graph to compress and coalesce redundancies in the data flow graph to simplify data flow, wherein the data flow graph is processed to determine points in the computer program at which data is received for argument values in the functions.
14 . The system of claim 9 , wherein the operations further comprise:
generating a data integrity policy indicating for the system call, the third argument value for the system call, a memory location in the memory where the third argument value received for the system call is written; and
processing, by the reference monitor, the data integrity policy to determine whether the fourth argument value passed to the system call has changed since the third argument value for the system call was written to the memory location.
15 . A method for implementing data flow integrity in a computer program, the method comprising:
generating instrumentation to determine whether argument values passed to function calls and system calls have changed since written to a memory during execution of the computer program;
providing a reference monitor that runs during execution of the computer program to perform:
comparing a first argument value of the argument values, for a function call, written to the memory, to a second argument value of the argument values passed to the function call, after the first argument value is received, to determine whether the second argument value has changed from the first argument value; and
permitting the execution of the function call with the second argument value in response to determining that the second argument value has not changed from the first argument value;
comparing a third argument value of the argument values, for a system call, written to the memory, to a fourth argument value of the argument values passed to the system call, after the third argument value is received, to determine whether the fourth argument value has changed from the third argument value; and
permitting the execution of the system call with the fourth argument value in response to determining that the fourth argument value has not changed from the third argument value.
16 . The method of claim 15 , wherein the reference monitor further performs during the execution of the computer program:
blocking the execution of the function call in response to determining that the second argument value has changed from the first argument value.
17 . The method of claim 15 , further comprising:
generating invariants to model how operations of functions, comprising the function calls and the system calls, modify the argument values passed to the functions to generate outputs without executing the functions;
using the invariants, during execution of the computer program, to determine whether the functions have processed the argument values passed to the functions as expected without executing the functions; and
generating an error in response to determining that an invariant of the invariants determines that one of the functions has not changed an argument value of the argument values as expected to generate the outputs.
18 . The method of claim 15 , wherein the reference monitor further performs, during the execution of the computer program:
in response to determining that the second argument value passed to the function call has not changed from the first argument value, calling an invariant of the invariants for the function call to determine whether the function call has modified the second argument value as expected to produce an output; and
continuing executing the computer program using the output from the function call in response to the invariant determining that the function call modified the second argument value as expected.
19 . The method of claim 15 , further comprising:
generating a function data graph analyzing functions, comprising the function calls and the system calls, to determine how the functions modify inputs to generate outputs;
generating a call graph indicating how the functions call each other in source code of the computer program;
performing inter-procedural alias analysis to determine a set of argument values of the argument values populated through pointers;
generating a data flow graph from the function data graph, the call graph, and the inter-procedural alias analysis; and
optimizing the data flow graph to compress and coalesce redundancies in the data flow graph to simplify data flow, wherein the data flow graph is processed to determine points in the computer program at which data is received for the argument values in the functions.