BinDSA: Efficient, Precise Binary-Level Pointer Analysis with Context-Sensitive Heap Reconstruction
Lian Gao, Heng Yin
Abstract
Pointer analysis serves as a fundamental component in the realm of binary code reverse engineering. It can be leveraged to reconstruct a binary program's call graph and can be further applied to various security analyses. However, the absence of symbols and type information within binary code presents formidable challenges to effective pointer analysis. Existing works often apply approximations when performing pointer analysis on binary. Nevertheless, these methods tend to be inefficient and produce numerous false positive targets. In this paper, we propose BinDSA, a novel model tailored for binary pointer analysis. BinDSA prioritizes precision and efficiency over soundness. It is field-and context-sensitive, employing unification-based techniques and reconstructing a context-sensitive heap. It jointly recovers data structure and points-to relations so that precision can be further improved. In evaluation, we demonstrate that BinDSA is 5 times more efficient and notably more precise than the current state-of-the-art technique without significantly sacrificing soundness. We also apply BinDSA on CVE reachability analysis and vulnerability detection, demonstrating its effective application to security tasks. CCS Concepts: • Security and privacy → Software reverse engineering; • Software and its engineering → Automated static analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext afbe2ba8-4ea5-46aa-92be-972296bed4fcCited by top-tier papers3
- Enhancing Semantic-Aware Binary Diffing with High-Confidence Dynamic Instruction AlignmentChengfeng Ye, Anshunkang Zhou, Charles ZhangNDSS 2026 · 2 citations
- Long-Range Indirect Control-Flow Prediction in Stripped Binaries via Dual Virtual Hubs and Multi-Task Graph LearningKun Liu, Zhengming Ding, Chenke Luo, Tianyi Xu et al.CCS 2026
- Analyzing Bytes: Pre-Disassembly Static Binary AnalysisHuan Nguyen, Soumyakant Priyadarshan, Chencheng Jiang, R. SekarPLDI 2026
Builds on11
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski et al.S&P 2016 · 227 citations
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes et al.S&P 2018 · 95 citations
- Automatically Detecting Error Handling Bugs Using Error SpecificationsSuman Jana, Yuan Jochen Kang, Samuel Roth, Baishakhi RayUSENIX Security 2016 · 79 citations
- OSPREY: Recovery of Variable and Data Structure via Probabilistic Analysis for Stripped BinaryZhuo Zhang, Yapeng Ye, Wei You, Guanhong Tao et al.S&P 2021 · 78 citations
- SelectiveTaint: Efficient Data Flow Tracking With Static Binary RewritingSanchuan Chen, Zhiqiang Lin, Yinqian ZhangUSENIX Security 2021 · 45 citations
Related papers
- Scalable, Sound, and Accurate Jump Table AnalysisHuan Nguyen, Soumyakant Priyadarshan, R. SekarISSTA 2024 · 3 citations
- Refining Indirect Call Targets at the Binary LevelSun Hyoung Kim, Cong Sun, Dongrui Zeng, Gang TanNDSS 2021
- Towards a Theoretically-Backed and Practical Framework for Selective Object-Sensitive Pointer AnalysisChaoyue Zhang, Longlong Lu, Yifei Lu, Minxue Pan et al.OOPSLA 2025
- MARX: Uncovering Class Hierarchies in C++ ProgramsAndre Pawlowski, Moritz Contag, Victor van der Veen, Chris Ouwehand et al.NDSS 2017 · 45 citations
- Learning graph-based heuristics for pointer analysis without handcrafting application-specific featuresMinseok Jeon, Myungho Lee, Hakjoo OhOOPSLA 2020 · 29 citations
