Representing and Reasoning about Dynamic Code
Jesse Bartels, Jon Stephens, Saumya Debray
Abstract
Dynamic code, i.e., code that is created or modified at runtime, is ubiquitous in today's world. The behavior of dynamic code can depend on the logic of the dynamic code generator in subtle and non-obvious ways, with significant security implications, e.g., JIT compiler bugs can lead to exploitable vulnerabilities in the resulting JIT-compiled code. Existing approaches to program analysis do not provide adequate support for reasoning about such behavioral relationships. This paper takes a first step in addressing this problem by describing a program representation and a new notion of dependency that allows us to reason about dependency and information flow relationships between the dynamic code generator and the generated dynamic code. Experimental results show that analyses based on these concepts are able to capture properties of dynamic code that cannot be identified using traditional program analyses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Capturing Malware Propagations with Code Injections and Code-Reuse AttacksDavid Korczynski, Heng YinCCS 2017 · 57 citations
- JITGuard: Hardening Just-in-time Compilers with SGXTommaso Frassetto, David Gens, Christopher Liebchen, Ahmad-Reza SadeghiCCS 2017 · 37 citations
Related papers
- Efficient module-level dynamic analysis for dynamic languages with module recontextualizationNikos Vasilakis, Grigoris Ntousakis, Veit Heller, Martin C. RinardFSE 2021 · 6 citations
- JVM fuzzing for JIT-induced side-channel detectionTegan Brennan, Seemanta Saha, Tevfik BultanICSE 2020 · 26 citations
- PatchScope: Memory Object Centric Patch DiffingLei Zhao, Yuncong Zhu, Jiang Ming, Yichen Zhang et al.CCS 2020 · 21 citations
- The ART of Sharing Points-to Analysis: Reusing Points-to Analysis Results Safely and EfficientlyShashin Halalingaiah, Vijay Sundaresan, Daryl Maier, V. Krishna NandivadaOOPSLA 2024 · 2 citations
- FlowDist: Multi-Staged Refinement-Based Dynamic Information Flow Analysis for Distributed Software SystemsXiaoqin Fu, Haipeng CaiUSENIX Security 2021 · 26 citations
