{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:20:06Z","timestamp":1780633206995,"version":"3.54.1"},"reference-count":76,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2021,12,24]],"date-time":"2021-12-24T00:00:00Z","timestamp":1640304000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["CCF-2100037 and CNS-2100015"],"award-info":[{"award-number":["CCF-2100037 and CNS-2100015"]}]},{"name":"NSA","award":["H98230-18-D-008"],"award-info":[{"award-number":["H98230-18-D-008"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2022,4,30]]},"abstract":"<jats:p>\n            Dynamic taint tracking, a technique that traces relationships between values as a program executes, has been used to support a variety of software engineering tasks. Some taint tracking systems only consider data flows and ignore control flows. As a result, relationships between some values are not reflected by the analysis. Many applications of taint tracking either benefit from or rely on these relationships being traced, but past works have found that tracking control flows resulted in over-tainting, dramatically reducing the precision of the taint tracking system. In this article, we introduce\n            <jats:sc>Conflux<\/jats:sc>\n            , alternative semantics for propagating taint tags along control flows.\n            <jats:sc>Conflux<\/jats:sc>\n            aims to reduce over-tainting by decreasing the scope of control flows and providing a heuristic for reducing loop-related over-tainting. We created a Java implementation of\n            <jats:sc>Conflux<\/jats:sc>\n            and performed a case study exploring the effect of\n            <jats:sc>Conflux<\/jats:sc>\n            on a concrete application of taint tracking, automated debugging. In addition to this case study, we evaluated\n            <jats:sc>Conflux<\/jats:sc>\n            \u2019s accuracy using a novel benchmark consisting of popular, real-world programs. We compared\n            <jats:sc>Conflux<\/jats:sc>\n            against existing taint propagation policies, including a state-of-the-art approach for reducing control-flow-related over-tainting, finding that\n            <jats:sc>Conflux<\/jats:sc>\n            had the highest F1 score on 43 out of the 48 total tests.\n          <\/jats:p>","DOI":"10.1145\/3485464","type":"journal-article","created":{"date-parts":[[2021,12,24]],"date-time":"2021-12-24T14:22:36Z","timestamp":1640355756000},"page":"1-43","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["A Practical Approach for Dynamic Taint Tracking with Control-flow Relationships"],"prefix":"10.1145","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4397-1635","authenticated-orcid":false,"given":"Katherine","family":"Hough","sequence":"first","affiliation":[{"name":"Northeastern University, Boston, MA, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1187-9298","authenticated-orcid":false,"given":"Jonathan","family":"Bell","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, MA, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,24]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/93548.93576"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.5555\/1177220"},{"key":"e_1_3_2_4_2","article-title":"Apache Commons Codec (version 1.14)","author":"Foundation Apache Software","year":"2019","unstructured":"Apache Software Foundation. 2019. Apache Commons Codec (version 1.14). Retrieved from http:\/\/commons.apache.org\/proper\/commons-codec\/.","journal-title":"Retrieved from http:\/\/commons.apache.org\/proper\/commons-codec\/"},{"key":"e_1_3_2_5_2","article-title":"Apache Commons Text (version 1.8)","author":"Foundation Apache Software","year":"2019","unstructured":"Apache Software Foundation. 2019. Apache Commons Text (version 1.8). Retrieved from https:\/\/commons.apache.org\/proper\/commons-text\/.","journal-title":"Retrieved from https:\/\/commons.apache.org\/proper\/commons-text\/"},{"key":"e_1_3_2_6_2","article-title":"Apache Tomcat (version 9.0.19)","author":"Foundation Apache Software","year":"2019","unstructured":"Apache Software Foundation. 2019. Apache Tomcat (version 9.0.19). Retrieved from https:\/\/tomcat.apache.org.","journal-title":"Retrieved from https:\/\/tomcat.apache.org"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594299"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.5555\/1924943.1924960"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/1831708.1831711"},{"key":"e_1_3_2_10_2","article-title":"Phosphor","author":"Bell Jonathan","year":"2014","unstructured":"Jonathan Bell and Gail Kaiser. 2014. Phosphor. Retrieved from https:\/\/github.com\/gmu-swe\/phosphor.","journal-title":"Retrieved from https:\/\/github.com\/gmu-swe\/phosphor"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2714064.2660212"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/2771783.2784768"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.37"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489241"},{"key":"e_1_3_2_15_2","article-title":"Checkstyle Commit 70c7ae0","author":"Contributors Checkstyle","year":"2020","unstructured":"Checkstyle Contributors. 2020. Checkstyle Commit 70c7ae0. Retrieved from https:\/\/github.com\/checkstyle\/checkstyle\/commit\/70c7ae0e1866074530a49c983d015936a0c2c10f.","journal-title":"Retrieved from https:\/\/github.com\/checkstyle\/checkstyle\/commit\/70c7ae0e1866074530a49c983d015936a0c2c10f"},{"key":"e_1_3_2_16_2","article-title":"Checkstyle Issue #8934","author":"Contributors Checkstyle","year":"2020","unstructured":"Checkstyle Contributors. 2020. Checkstyle Issue #8934. Retrieved from https:\/\/github.com\/checkstyle\/checkstyle\/issues\/8934.","journal-title":"Retrieved from https:\/\/github.com\/checkstyle\/checkstyle\/issues\/8934"},{"key":"e_1_3_2_17_2","article-title":"Checkstyle (version 8.37)","author":"Contributors Checkstyle","year":"2020","unstructured":"Checkstyle Contributors. 2020. Checkstyle (version 8.37). Retrieved from https:\/\/github.com\/checkstyle\/checkstyle.","journal-title":"Retrieved from https:\/\/github.com\/checkstyle\/checkstyle"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/1655121.1655125"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/1273463.1273490"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/1572272.1572301"},{"key":"e_1_3_2_21_2","article-title":"Google Closure Compiler Commit aac5d11","author":"Authors Closure Compiler","year":"2014","unstructured":"Closure Compiler Authors. 2014. Google Closure Compiler Commit aac5d11. Retrieved from https:\/\/github.com\/google\/closure-compiler\/commit\/aac5d11480a0ed3f37919c23a5d3cc210e534bd5.","journal-title":"Retrieved from https:\/\/github.com\/google\/closure-compiler\/commit\/aac5d11480a0ed3f37919c23a5d3cc210e534bd5"},{"key":"e_1_3_2_22_2","article-title":"Google Closure Compiler Issue #652","author":"Authors Closure Compiler","year":"2014","unstructured":"Closure Compiler Authors. 2014. Google Closure Compiler Issue #652. Retrieved from https:\/\/github.com\/google\/closure-compiler\/issues\/652.","journal-title":"Retrieved from https:\/\/github.com\/google\/closure-compiler\/issues\/652"},{"key":"e_1_3_2_23_2","article-title":"Google Closure Compiler (version v20140814)","author":"Authors Closure Compiler","year":"2014","unstructured":"Closure Compiler Authors. 2014. Google Closure Compiler (version v20140814). Retrieved from https:\/\/github.com\/google\/closure-compiler.","journal-title":"Retrieved from https:\/\/github.com\/google\/closure-compiler"},{"key":"e_1_3_2_24_2","volume-title":"A Simple, Fast Dominance Algorithm","author":"Cooper Keith","year":"2006","unstructured":"Keith Cooper, Timothy Harvey, and Ken Kennedy. 2006. A Simple, Fast Dominance Algorithm. Rice University, CS Technical Report 06-33870. Rice University."},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671256"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/115372.115320"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/359636.359712"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.5555\/1924943.1924971"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"e_1_3_2_30_2","article-title":"Guava (version 28.2-jre)","author":"LLC Google","year":"2020","unstructured":"Google LLC. 2020. Guava (version 28.2-jre). Retrieved from https:\/\/github.com\/google\/guava.","journal-title":"Retrieved from https:\/\/github.com\/google\/guava"},{"key":"e_1_3_2_31_2","article-title":"H2 Commit 6c564e6","author":"Contributors H2","year":"2020","unstructured":"H2 Contributors. 2020. H2 Commit 6c564e6. Retrieved from https:\/\/github.com\/h2database\/h2database\/commit\/6c564e63eb6a3c819eaab19f4aece3298db2ab5f.","journal-title":"Retrieved from https:\/\/github.com\/h2database\/h2database\/commit\/6c564e63eb6a3c819eaab19f4aece3298db2ab5f"},{"key":"e_1_3_2_32_2","article-title":"H2 Issue #2550","author":"Contributors H2","year":"2020","unstructured":"H2 Contributors. 2020. H2 Issue #2550. Retrieved from https:\/\/github.com\/h2database\/h2database\/issues\/2550.","journal-title":"Retrieved from https:\/\/github.com\/h2database\/h2database\/issues\/2550"},{"key":"e_1_3_2_33_2","article-title":"H2 (version 1.4.200)","author":"Contributors H2","year":"2020","unstructured":"H2 Contributors. 2020. H2 (version 1.4.200). Retrieved from https:\/\/github.com\/h2database\/h2database\/.","journal-title":"Retrieved from https:\/\/github.com\/h2database\/h2database\/"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/1181775.1181797"},{"key":"e_1_3_2_35_2","article-title":"A Practical Approach for Dynamic Taint Tracking with Control-Flow Relationships (Artifact)","author":"Hough Katherine","year":"2021","unstructured":"Katherine Hough and Jonathan Bell. 2021. A Practical Approach for Dynamic Taint Tracking with Control-Flow Relationships (Artifact). DOI:https:\/\/doi.org\/10.6084\/m9.figshare.16611424.v1","journal-title":"DOI:https:\/\/doi.org\/10.6084\/m9.figshare.16611424.v1"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380326"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635917"},{"key":"e_1_3_2_38_2","volume-title":"On Efficiency and Accuracy of Data Flow Tracking Systems","author":"Jee Kangkook","year":"2015","unstructured":"Kangkook Jee. 2015. On Efficiency and Accuracy of Data Flow Tracking Systems. Ph.D. Dissertation. Columbia University. DOI:https:\/\/doi.org\/10.7916\/D8MG7P9D"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134607"},{"key":"e_1_3_2_40_2","article-title":"jsoup: Java HTML Parser (version 1.11.3)","author":"Hedley Jonathan","year":"2018","unstructured":"Jonathan Hedley. 2018. jsoup: Java HTML Parser (version 1.11.3). Retrieved from https:\/\/jsoup.org\/.","journal-title":"Retrieved from https:\/\/jsoup.org\/"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/2610384.2628055"},{"key":"e_1_3_2_42_2","volume-title":"Proceedings of the Network and Distributed System Security Symposium","author":"Kang Min Gyung","year":"2011","unstructured":"Min Gyung Kang, Stephen McCamant, Pongsin Poosankam, and Dawn Xiaodong Song. 2011. DTA++: Dynamic taint analysis with targeted control-flow propagation. In Proceedings of the Network and Distributed System Security Symposium."},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89862-7_4"},{"key":"e_1_3_2_44_2","article-title":"Bouncy Castle Provider (version 1.46)","author":"Inc. Legion of the Bouncy Castle","year":"2011","unstructured":"Legion of the Bouncy Castle Inc.2011. Bouncy Castle Provider (version 1.46). Retrieved from http:\/\/bouncycastle.org\/.","journal-title":"Retrieved from http:\/\/bouncycastle.org\/"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.5555\/2636992"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/1379022.1375606"},{"key":"e_1_3_2_47_2","article-title":"Mozilla Rhino Commit 0c0bb39","author":"Contributors MDN","year":"2019","unstructured":"MDN Contributors. 2019. Mozilla Rhino Commit 0c0bb39. Retrieved from https:\/\/github.com\/mozilla\/rhino\/commit\/0c0bb391647600ec706b1ec66f71831893a6f564.","journal-title":"Retrieved from https:\/\/github.com\/mozilla\/rhino\/commit\/0c0bb391647600ec706b1ec66f71831893a6f564"},{"key":"e_1_3_2_48_2","article-title":"Mozilla Rhino Issue #539","author":"Contributors MDN","year":"2019","unstructured":"MDN Contributors. 2019. Mozilla Rhino Issue #539. Retrieved from https:\/\/github.com\/mozilla\/rhino\/issues\/539.","journal-title":"Retrieved from https:\/\/github.com\/mozilla\/rhino\/issues\/539"},{"key":"e_1_3_2_49_2","article-title":"Mozilla Rhino (version 1.7.11)","author":"Contributors MDN","year":"2019","unstructured":"MDN Contributors. 2019. Mozilla Rhino (version 1.7.11). Retrieved from https:\/\/github.com\/mozilla\/rhino.","journal-title":"Retrieved from https:\/\/github.com\/mozilla\/rhino"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3293882.3338983"},{"key":"e_1_3_2_51_2","unstructured":"James Newsome and Dawn Song. 2005. Dynamic taint analysis for automatic detection analysis and signature generation of exploits on commodity software. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201905) ."},{"key":"e_1_3_2_52_2","article-title":"OpenRefine Commit 825e687","author":"Contributors OpenRefine","year":"2020","unstructured":"OpenRefine Contributors. 2020. OpenRefine Commit 825e687. Retrieved from https:\/\/github.com\/OpenRefine\/OpenRefine\/commit\/825e687b0b676fd1be1fa0a9d00be22de0e57060.","journal-title":"Retrieved from https:\/\/github.com\/OpenRefine\/OpenRefine\/commit\/825e687b0b676fd1be1fa0a9d00be22de0e57060"},{"key":"e_1_3_2_53_2","article-title":"OpenRefine Issue #2584","author":"Contributors OpenRefine","year":"2020","unstructured":"OpenRefine Contributors. 2020. OpenRefine Issue #2584. Retrieved from https:\/\/github.com\/OpenRefine\/OpenRefine\/issues\/2584.","journal-title":"Retrieved from https:\/\/github.com\/OpenRefine\/OpenRefine\/issues\/2584"},{"key":"e_1_3_2_54_2","article-title":"OpenRefine (version 3.4-SNAPSHOT)","author":"contributors OpenRefine","year":"2020","unstructured":"OpenRefine contributors. 2020. OpenRefine (version 3.4-SNAPSHOT). Retrieved from https:\/\/github.com\/OpenRefine\/OpenRefine.","journal-title":"Retrieved from https:\/\/github.com\/OpenRefine\/OpenRefine"},{"key":"e_1_3_2_55_2","article-title":"OpenJDK Java Class Library (version 1.8.0_222)","author":"Corporation Oracle","year":"2019","unstructured":"Oracle Corporation. 2019. OpenJDK Java Class Library (version 1.8.0_222). Retrieved from https:\/\/openjdk.java.net\/.","journal-title":"Retrieved from https:\/\/openjdk.java.net\/"},{"key":"e_1_3_2_56_2","article-title":"ASM (version 7.1)","author":"Consortium OW2","year":"2019","unstructured":"OW2 Consortium. 2019. ASM (version 7.1). Retrieved from https:\/\/asm.ow2.io\/.","journal-title":"Retrieved from https:\/\/asm.ow2.io\/"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236029"},{"key":"e_1_3_2_58_2","article-title":"Spring Framework (version 5.2.5)","author":"Software Pivotal","year":"2020","unstructured":"Pivotal Software. 2020. Spring Framework (version 5.2.5). Retrieved from https:\/\/spring.io\/projects\/spring-framework.","journal-title":"Retrieved from https:\/\/spring.io\/projects\/spring-framework"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2006.29"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23404"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1145\/3139337.3139341"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.26"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/2750858.2804260"},{"key":"e_1_3_2_65_2","volume-title":"Advancing Practical Specification Techniques for Modern Software Systems","author":"Singleton John","year":"2018","unstructured":"John Singleton. 2018. Advancing Practical Specification Techniques for Modern Software Systems. Ph.D. Dissertation. University of Central Florida. Retrieved from http:\/\/purl.fcla.edu\/fcla\/etd\/CFE0007099."},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/1273442.1250748"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338504.3357339"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.5555\/869354"},{"key":"e_1_3_2_69_2","series-title":"Proceedings of the 30th European Conference on Object-oriented Programming (ECOOP\u201916)","first-page":"24:1\u201324:25","volume":"56","author":"Toman John","year":"2016","unstructured":"John Toman and Dan Grossman. 2016. Staccato: A bug finder for dynamic configuration updates. In Proceedings of the 30th European Conference on Object-oriented Programming (ECOOP\u201916)(Leibniz International Proceedings in Informatics (LIPIcs), Vol. 56), Shriram Krishnamurthi and Benjamin S. Lerner (Eds.). Schloss Dagstuhl\u2013Leibniz-Zentrum fuer Informatik, Dagstuhl, Germany, 24:1\u201324:25. DOI:https:\/\/doi.org\/10.4230\/LIPIcs.ECOOP.2016.24"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00100"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.37"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1984.5010248"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/1273463.1273489"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/32.988498"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/1133981.1134002"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1145\/996893.996855"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.5555\/776816.776855"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485464","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485464","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485464","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:30:15Z","timestamp":1750188615000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485464"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,24]]},"references-count":76,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,4,30]]}},"alternative-id":["10.1145\/3485464"],"URL":"https:\/\/doi.org\/10.1145\/3485464","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,12,24]]},"assertion":[{"value":"2021-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-12-24","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}