Taint Lite

Privacy leak detector for IMP-Core and Python — CS 336 Project 9, Team 9


What it does

Taint Lite performs static taint analysis to detect when Personally Identifiable Information (PII) flows from a source (e.g. get_email()) to a dangerous sink (e.g. log()). It supports both IMP-Core (.imp) and real Python (.py) source files, and accepts a JSON policy file to define custom sources and sinks.

Installation

Requires Python 3.9+. No external runtime dependencies.

git clone https://github.com/Justinv1234/cs336-p9-team9.git
cd cs336-p9-team9
pip3 install pytest   # only needed to run tests

Usage

python3 src/main.py <file.imp | file.py> [--policy policy.json]

Exits with code 0 if no leaks found, 1 if leaks are detected.

Examples

1. Basic IMP leak

# examples/basic.imp
email := get_email()
name  := get_name()
user_info := email + " - " + name
log(user_info)         # Privacy leak!
send_analytics(name)   # Another leak!
$ python3 src/main.py examples/basic.imp

PII LEAK at line 4
  Sink: log
  PII types exposed: {email, name}
  Recommendation: Redact PII before logging

PII LEAK at line 5
  Sink: send_analytics
  PII types exposed: {name}
  Recommendation: Anonymize before sending to analytics

2. Python webapp leak

# examples/webapp_leak.py
email = get_email(user_id)
name  = get_name(user_id)
ssn   = get_ssn(user_id)

logging.info(f"Processing request for {email}")   # LEAK
send_analytics({"user": name})                     # LEAK
send_to_api("https://internal/verify", data={"ssn": ssn})  # LEAK
$ python3 src/main.py examples/webapp_leak.py

PII LEAK at line 25
  Sink: logging.info
  PII types exposed: {email}
  Recommendation: Redact PII before logging

PII LEAK at line 28
  Sink: send_analytics
  PII types exposed: {name}
  Recommendation: Anonymize before sending to analytics

PII LEAK at line 36
  Sink: send_to_api
  PII types exposed: {ssn}
  Recommendation: Remove PII before sending to external sink

3. No leak

$ python3 src/main.py examples/no_leak.imp
No PII leaks detected.

4. Chained propagation

# examples/chained.imp
email := get_email()
a := email
b := a
c := b + " extra"
log(c)
$ python3 src/main.py examples/chained.imp

PII LEAK at line 5
  Sink: log
  PII types exposed: {email}
  Recommendation: Redact PII before logging

5. Custom policy

# examples/custom_policy.json
{
  "sources": {
    "fetch_credit_card": "credit_card",
    "get_passport_number": "passport"
  },
  "sinks": {
    "kafka_publish": "Remove PII before publishing to Kafka",
    "s3_upload": "Encrypt PII before uploading to S3"
  }
}
$ python3 src/main.py examples/custom_policy_demo.py --policy examples/custom_policy.json

PII LEAK at line 20
  Sink: kafka_publish
  PII types exposed: {credit_card}
  Recommendation: Remove PII before publishing to Kafka

PII LEAK at line 23
  Sink: s3_upload
  PII types exposed: {passport}
  Recommendation: Encrypt PII before uploading to S3

Running the tests

python3 -m pytest tests/ -v

51 tests across 5 modules, all passing.

FileTestsCovers
test_lexer.py6Tokenizer: comments, line numbers, operators
test_parser.py7Parser: assignments, sink calls, binary ops, AST nodes
test_taint.py10IMP taint engine: propagation, sinks, recommendations
test_policy.py8Policy loading: merge, custom sources/sinks, error handling
test_python_analyzer.py20Python analyzer: f-strings, dicts, chaining, custom policy

Built-in sources & sinks

Source functionPII tag
get_email()email
get_name()name
get_ssn()ssn
get_phone()phone
get_address()address
get_dob()date_of_birth
get_user_id()user_id
Sink functionRecommendation
logRedact PII before logging
send_analyticsAnonymize before sending to analytics
send_to_apiRemove PII before sending to external sink
print_logRedact PII before logging
write_logRedact PII before logging
post_to_serverRemove PII before sending to external sink

Any function whose name contains log, analytics, api, server, report, track, or monitor is also treated as a sink.


CS 336 · Project 9 · Team 9 — Justin Veltri, Flavia Daniels, Arnav Vasa, Garrett Boag, Jonathan Veltri