Applying System Call Filtering to Real-World Binaries (Experience Paper)
Soumyakant Priyadarshan, Seyedhamed Ghavamnia
Abstract
System call filtering restricts applications to the system calls they require, but inferring accurate syscall sets for binary-only programs remains challenging. A central difficulty lies in recovering precise control-flow information from binaries: over-approximation leads to overly permissive syscall filters, while missed control-flow edges result in unsound policies. Although many techniques have been proposed to improve control-flow recovery in binaries, their practical impact on syscall inference remains poorly understood. In this work, we conduct an empirical study of syscall inference from binaries using multiple off-the-shelf binary analysis tools. We evaluate how different control-flow refinement techniques affect inferred syscall sets in practice. Our experiments on real-world applications show that refinements targeting individual control-flow transfers (e.g., call-site and callee argument matching) substantially improve per-call target precision but often do not reduce the overall syscall set. In contrast, techniques that reduce the global set of address-taken functions---such as leveraging relocation information to accurately identify code pointers---yield the most significant syscall reductions. Finally, we identify a practical lower bound on syscall reduction achievable via sound static binary analysis alone, and show that further improvements are likely to require configuration or workload-aware specialization.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 16bbe40a-4ff4-48bd-9c4d-bae7b9d4e67cRelated papers
- When Function Signature Recovery Meets Compiler OptimizationYan Lin, Debin GaoS&P 2021 · 22 citations
- Refining Indirect Call Targets at the Binary LevelSun Hyoung Kim, Cong Sun, Dongrui Zeng, Gang TanNDSS 2021
- Semantics-Guided Control-Flow Reconstruction for Firmware Binaries via Static AnalysisFengjuan Gao, Qingjie Zhu, Yi Zhang, Yu Wang et al.FSE 2026
- Improving Indirect-Call Analysis in LLVM with Type and Data-Flow Co-AnalysisDinghao Liu, Shouling Ji, Kangjie Lu, Qinming HeUSENIX Security 2024 · 13 citations
- TypeSqueezer: When Static Recovery of Function Signatures for Binary Executables Meets Dynamic AnalysisZiyi Lin, Jinku Li, Bowen Li, Haoyu Ma et al.CCS 2023 · 7 citations
