Repository navigation
Are you using Tai-e? #66
Description
Activity
- pinned this issue
on Oct 22, 2023 Organization/Company: Fudan University
Country/Region: China
Contact: 23110240120@m.fudan.edu.cn
Usage scenario: Using Tai-e to develop static analysis toolsReacted by Qianheng Wang, RacerZ, 1kuzus, zsy-arch and FoggyDawnOrganization/Company: Meituan Mobile Security Team
Country/Region: China
Contact: Yaphetsh@outlook.com
Usage scenario: Using Tai-e to Mobile Security Research and DevelopmentOrganization/Company: Personal
Country/Region: Singapore
Contact: voidness1023@gmail.com
Usage scenario: Using Tai-e to develop static analysis toolsOrganization/Company: Huawei
Country/Region: China
Contact: liyiwei14@huawei.com
Usage scenario: referring to Tai-e for implementing my own program analysis toolsOrganization/Company: ByteDance
Country/Region: China
Contact: liujie.jl@bytedance.com
Usage scenario: referring to the design from tai-e to develop our own static analysis frameworkOrganization/Company: AntGroup
Country/Region: China
Contact: wudiyu.wdy@antgroup.com
Usage scenario: referring to Tai-e for our own program analysis platformOrganization/Company: University of Chinese Academy of Sciences
Country/Region: China
Contact: owhvayifuqq@gmail.com
Usage scenario: Using Tai-e to extract useful information, such as call graphs and so onOrganization/Company: ZheJiang University
Country/Region: China
Contact: wuzhiyao@zju.edu.cn
Usage scenario: Using Tai-e for taint analysis and generating call graph.Organization/Company: Southeast University
Country/Region: China
Contact: 220235339@seu.edu.cn
Usage scenario: Using Tai-e to develop a tool for analyzing Spring projects.Organization/Company: Nankai University
Country/Region: China
Contact: yuhao.liu@mail.nankai.edu.cn
Usage scenario: Using Tai-e for
(1) learning and implementing custom static analysis,
(2) conducting research in software misconfigurations for addressing detecting/diagnosing/validation problem.Organization/Company: Zhejiang University
Country/Region: China
Contact: yixuanbu@zju.edu.cn
Usage scenario: Using Tai-e to conducting research in program analysis for addressing Influence of call site reachabilityOrganization/Company: Independent (personal open-source project)
Country/Region: Brazil
Contact: https://github.com/GabrielBBaldezUsage scenario: I built spring-taint, an interprocedural taint analyzer for Spring Boot, on top of Tai-e. A thin Spring layer registers controller/listener entry points and emits param/call sources for Spring annotations (
@RequestParam,@RequestBody,@KafkaListener,@RabbitListener,@FeignClient, JAX-RS/Micronaut, ...), and Tai-e's call graph, pointer analysis and IFDS taint analysis do the heavy lifting -- flagging source->sink flows that cross controller/service/repository layers, which same-method scanners miss. It detects SQL/JPQL injection, XSS, SSRF, SpEL/JNDI/template injection, path traversal, command injection and open redirect, and ships as a CLI, a Docker image and a GitHub Action (SARIF 2.1, now on the Marketplace).The
TaintConfigProvider/Pluginextension points and call-site-mode sink matching made the Spring modeling clean to layer on. Thanks for the framework!Reacted by Teng ZhangReacted by Jinpeng Wang and inmaldrerah
The Purpose of This Issue
We are consistently eager to learn more about Tai-e users, understand what led you to choose our framework, attentively address your requirements, and help promote your work on program analysis.
What We Would Like To Hear From You
We kindly ask that you submit a comment in this issue to provide the following information:
For example:
We will pay attention to this issue.
Whether you are from a company or a university, we encourage you to leave your usage information of Tai-e.
We will prioritize addressing the problems and needs of users who leave usage information in this issue.