Practical Program Modularization with Type-Based Dependence Analysis
Kangjie Lu
Abstract
Today's software programs are bloating and have become extremely complex. As there is typically no internal isolation among modules in a program, a vulnerability can be exploited to corrupt the memory and take control of the whole program. Program modularization is thus a promising security mechanism that splits a complex program into smaller modules, so that memory-access instructions can be constrained from corrupting irrelevant modules. A general approach to realizing program modularization is dependence analysis which determines if an instruction is independent of specific code or data; and if so, it can be modularized. Unfortunately, dependence analysis in complex programs is generally considered infeasible, due to problems in data-flow analysis, such as unknown indirect-call targets, pointer aliasing, and path explosion. As a result, we have not seen practical automated program modularization built on dependence analysis.This paper presents a breakthrough—Type-based dependence analysis for Program Modularization (TyPM). Its goal is to determine which modules in a program can never pass a type of object (including references) to a memory-access instruction; therefore, objects of this type that are created by these modules can never be valid targets of the instruction. The idea is to employ a type-based analysis to first determine which types of data flows can take place between two modules, and then transitively resolve all dependent modules of a memory-access instruction, with respect to the specific type. Such an approach avoids the data-flow analysis and can be practical. We develop two important security applications based on TyPM: refining indirect-call targets and protecting critical data structures. We extensively evaluate TyPM with various system software, including an OS kernel, a hypervisor, UEFI firmware, and a browser. Results show that on average TyPM additionally refines indirect-call targets produced by the state of the art by 31%-91%. TyPM can also remove 99.9% of modules for memory-write instructions to prevent them from corrupting critical data structures in the Linux kernel.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 80e25a87-018a-4c7a-a152-10d0084d8e02Cited by top-tier papers16
- SDFuzz: Target States Driven Directed FuzzingPenghui Li, Wei Meng, Chao ZhangUSENIX Security 2024 · 16 citations
- Improving Indirect-Call Analysis in LLVM with Type and Data-Flow Co-AnalysisDinghao Liu, Shouling Ji, Kangjie Lu, Qinming HeUSENIX Security 2024 · 13 citations
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie et al.USENIX Security 2024 · 6 citations
- Type-Alias Analysis: Enabling LLVM IR with Accurate TypesJinmeng Zhou, Ziyue Pan, Wenbo Shen, Xingkai Wang et al.ISSTA 2025 · 1 citation
- Diatom: Polylithic Binary Lifting with Data-Flow Summaries and Type-Aware IR LinkingAnshunkang Zhou, Charles ZhangOOPSLA 2026 · 1 citation
Builds on15
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 153 citations
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 142 citations
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris et al.NDSS 2016 · 141 citations
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
Related papers
- Redefining Indirect Call Analysis with KallGraphGuoren Li, Manu Sridharan, Zhiyun QianS&P 2025
- MAKO: Refining Indirect-Call Targets with Type Relation UnfoldingYibo Jin, Wei Chen, Bowen Zhang, Charles ZhangCCS 2026
- DEEPTYPE: Refining Indirect Call Targets with Strong Multi-layer Type AnalysisTianrou Xia, Hong Hu, Dinghao WuUSENIX Security 2024 · 13 citations
- Mitigating Information Leakage Vulnerabilities with Type-based Data IsolationAlyssa Milburn, Erik van der Kouwe, Cristiano GiuffridaS&P 2022 · 16 citations
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski et al.S&P 2016 · 227 citations
