Meaning
Security monitoring of data flow from untrusted sources prevents the execution of malicious commands within an embedded system. Dynamic taint tracking firmware marks incoming data from network or serial ports as tainted and follows its path through memory and registers. If this tainted data reaches a sensitive area like a jump instruction or a system call, the execution is stopped.
Data Propagation
Markings are moved along with the data as it is copied from one location to another. When dynamic taint tracking firmware is active, the system monitors every arithmetic and logic operation to see if the result is influenced by a tainted input. This provides a way to detect injection attacks that try to take control of the program flow.
Security Policy
Rules define which sources are considered untrusted and which sinks are considered sensitive. If a piece of data from an unauthenticated radio link is used to calculate a memory address, the dynamic taint tracking firmware flags this as a policy violation. The response can range from logging the event to a full system reset.
Performance Impact
Monitoring every data movement adds significant overhead to the processor. Dedicated hardware accelerators are often used to reduce the time spent checking taint status.