{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T23:04:17Z","timestamp":1784156657037,"version":"3.55.0"},"reference-count":34,"publisher":"World Scientific Pub Co Pte Ltd","issue":"04","funder":[{"name":"Excellent Scientific Research and Innovation Team of Anhui Colleges","award":["2022AH010098"],"award-info":[{"award-number":["2022AH010098"]}]},{"name":"Key Research Projects of Universities in Anhui Province","award":["2024AH051366"],"award-info":[{"award-number":["2024AH051366"]}]},{"name":"Key Research Projects of Universities in Anhui Province","award":["2024AH051368"],"award-info":[{"award-number":["2024AH051368"]}]},{"name":"the Industry-University Cooperative Education Project by the Ministry of Education","award":["231107601104332"],"award-info":[{"award-number":["231107601104332"]}]},{"name":"the High-level Talent Research Start-up Fund of Chizhou University","award":["CZ2024YJRC03"],"award-info":[{"award-number":["CZ2024YJRC03"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int. J. Soft. Eng. Knowl. Eng."],"published-print":{"date-parts":[[2025,4]]},"abstract":"<jats:p> One of the most effective methods for detecting software security vulnerabilities is taint analysis. Some software defects originate from certain external input data. Analyzing the taint sources and the data flow propagation from these sources to defect points through static analysis can help us understand the causes of software defects and reduce the difficulty of debugging them. This paper combines intraprocedural and interprocedural analysis methods to obtain global taint source information. A novel propagation path calculation algorithm is proposed, incorporating predecessor node computation and alias analysis, effectively reducing the negative impact of irrelevant code on the performance of taint analysis. This method not only helps detect errors that lead to vulnerabilities but also analyzes the impact of vulnerable input data on the system. Based on the global taint source analysis algorithm, we developed a static taint source analysis prototype tool for C programs, called AWsTS. Experiments conducted on five open-source projects show that AWsTS improves the accuracy of analysis results without increasing the required analysis time. The average precision for intra-procedural taint source analysis is 93.4%, and the average recall is 90.2%. Similarly, for interprocedural taint source analysis, the average precision is 87.6%, and the average recall is 84.9%. Additionally, AWsTS can output taint propagation paths, providing valuable support for further taint analysis. <\/jats:p>","DOI":"10.1142\/s0218194025500123","type":"journal-article","created":{"date-parts":[[2025,1,10]],"date-time":"2025-01-10T10:03:22Z","timestamp":1736503402000},"page":"469-501","source":"Crossref","is-referenced-by-count":3,"title":["A Static Analysis Framework for Investigating Tainted Data Sources in Software Systems"],"prefix":"10.1142","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1919-2498","authenticated-orcid":false,"given":"Peng","family":"Dai","sequence":"first","affiliation":[{"name":"Anhui Education Big Data Intelligent Perception and Application Engineering Research Center, Chizhou University, Chizhou 247000, P.\u00a0R.\u00a0China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9428-3505","authenticated-orcid":false,"given":"Xiaoqin","family":"Ma","sequence":"additional","affiliation":[{"name":"Anhui Education Big Data Intelligent Perception and Application Engineering Research Center, Chizhou University, Chizhou 247000, P.\u00a0R.\u00a0China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zebo","family":"Peng","sequence":"additional","affiliation":[{"name":"Anhui Provincial Joint Construction Key Laboratory of Intelligent Education Equipment and Technology, Chizhou 247000, P.\u00a0R.\u00a0China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8614-5080","authenticated-orcid":false,"given":"Chen","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Ningbo University of Technology, Ningbo 315211, P.\u00a0R.\u00a0China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6263-7144","authenticated-orcid":false,"given":"Qianjin","family":"Zhang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing 100876, P.\u00a0R.\u00a0China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"219","published-online":{"date-parts":[[2025,3,21]]},"reference":[{"key":"S0218194025500123BIB002","volume-title":"Notes. Feb","author":"M\u00f8ller A.","year":"2012"},{"issue":"6","key":"S0218194025500123BIB003","first-page":"231","volume":"13","author":"Alashjee A. M.","year":"2019","journal-title":"Int. J. Comput. Sci. Secur."},{"key":"S0218194025500123BIB004","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00040"},{"key":"S0218194025500123BIB005","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102161"},{"issue":"4","key":"S0218194025500123BIB006","first-page":"860","volume":"28","author":"Wang L.","year":"2017","journal-title":"J. Softw."},{"key":"S0218194025500123BIB007","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594299"},{"key":"S0218194025500123BIB008","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.48"},{"key":"S0218194025500123BIB009","doi-asserted-by":"publisher","DOI":"10.1145\/3183575"},{"key":"S0218194025500123BIB010","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23089"},{"key":"S0218194025500123BIB011","doi-asserted-by":"publisher","DOI":"10.1145\/3341105.3373924"},{"key":"S0218194025500123BIB012","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2015.2457411"},{"key":"S0218194025500123BIB013","doi-asserted-by":"publisher","DOI":"10.1145\/2931037.2931041"},{"key":"S0218194025500123BIB014","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103186"},{"key":"S0218194025500123BIB018","doi-asserted-by":"publisher","DOI":"10.1109\/ICoDSE48700.2019.9092614"},{"key":"S0218194025500123BIB019","doi-asserted-by":"publisher","DOI":"10.1002\/smr.233"},{"issue":"6","key":"S0218194025500123BIB020","first-page":"1701","volume":"32","author":"Zhang J.","year":"2021","journal-title":"J. Softw."},{"key":"S0218194025500123BIB021","first-page":"3","volume-title":"Network and Distributed System Security Symp.","author":"Newsome J.","year":"2005"},{"key":"S0218194025500123BIB022","doi-asserted-by":"publisher","DOI":"10.1016\/S1571-0661(04)81042-9"},{"key":"S0218194025500123BIB024","doi-asserted-by":"publisher","DOI":"10.1145\/1273463.1273490"},{"key":"S0218194025500123BIB025","doi-asserted-by":"publisher","DOI":"10.1145\/2151024.2151042"},{"key":"S0218194025500123BIB026","doi-asserted-by":"publisher","DOI":"10.1145\/1064978.1065034"},{"key":"S0218194025500123BIB027","doi-asserted-by":"publisher","DOI":"10.1145\/2619091"},{"key":"S0218194025500123BIB029","first-page":"31","volume-title":"22nd Int. Symp. Research in Attacks, Intrusions and Defenses","author":"Davanian A.","year":"2019"},{"key":"S0218194025500123BIB030","doi-asserted-by":"publisher","DOI":"10.1631\/FITEE.2000709"},{"key":"S0218194025500123BIB031","doi-asserted-by":"publisher","DOI":"10.1145\/390011.808263"},{"key":"S0218194025500123BIB032","doi-asserted-by":"publisher","DOI":"10.1145\/1543135.1542486"},{"key":"S0218194025500123BIB033","doi-asserted-by":"publisher","DOI":"10.1016\/j.measurement.2019.107139"},{"key":"S0218194025500123BIB034","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00022"},{"key":"S0218194025500123BIB035","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2021.10.039"},{"key":"S0218194025500123BIB036","doi-asserted-by":"publisher","DOI":"10.1109\/ICPC.2019.00031"},{"key":"S0218194025500123BIB037","doi-asserted-by":"publisher","DOI":"10.1109\/OTCON56053.2023.10113963"},{"key":"S0218194025500123BIB038","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM.2008.12"},{"key":"S0218194025500123BIB040","volume-title":"35th Int. Conf. Chilean Computer Science Society","author":"Arroyo M.","year":"2017"},{"key":"S0218194025500123BIB041","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-17465-1_22"}],"container-title":["International Journal of Software Engineering and Knowledge Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.worldscientific.com\/doi\/pdf\/10.1142\/S0218194025500123","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,25]],"date-time":"2025-04-25T05:33:59Z","timestamp":1745559239000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.worldscientific.com\/doi\/10.1142\/S0218194025500123"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,21]]},"references-count":34,"journal-issue":{"issue":"04","published-print":{"date-parts":[[2025,4]]}},"alternative-id":["10.1142\/S0218194025500123"],"URL":"https:\/\/doi.org\/10.1142\/s0218194025500123","relation":{},"ISSN":["0218-1940","1793-6403"],"issn-type":[{"value":"0218-1940","type":"print"},{"value":"1793-6403","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,21]]}}}