Protecting Source Code Privacy When Hunting Memory Bugs
Jielun Wu, Bing Shui, Hongcheng Fan, Shengxin Wu, Rongxin Wu, Yang Feng, Baowen Xu, Qingkai Shi
Abstract
When proving to a third party that a software system is free from critical memory bugs, software vendors often face the problem of having to reveal their source code, so that the third party can scan the source code using static analysis tools. However, such transparency poses a significant threat to vendors, as the source code typically contains proprietary algorithms, core technical innovations, or trade secrets, exposing them to potential intellectual property risks. In this paper, we present a solution that offers a balance between transparency and code privacy, allowing software vendors to provide minimal source code information while justifying the sufficiency of bug detection. To this end, we propose DIReducer, which reduces source code information, a.k.a. debug information, from non-stripped binaries while preserving its utility for memory bug detection. DIReducer consists of two components: selective pruning and type minimization. The former eliminates redundant debug information, and the latter is proven to be NP-hard and minimizes type-related debug information by reducing it to the classic set-cover problem, which offers a near-optimal solution. Experimental results show that we can reduce 95% of debug information while maintaining similar bug detection capability compared to using full debug information or the source code.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bb702da8-78b4-4920-aabb-fa447322af54Builds on21
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- Debin: Predicting Debug Information in Stripped BinariesJingxuan He, Pesho Ivanov, Petar Tsankov, Veselin Raychev et al.CCS 2018 · 148 citations
- SoK: All You Ever Wanted to Know About x86/x64 Binary Disassembly But Were Afraid to AskChengbin Pang, Ruotong Yu, Yaohui Chen, Eric Koskinen et al.S&P 2021 · 102 citations
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer et al.CCS 2016 · 97 citations
Related papers
- Keeping Secrets: Multi-objective Genetic Improvement for Detecting and Reducing Information LeakageIbrahim Mesecan, Daniel Blackwell, David Clark, Myra B. Cohen et al.ASE 2022 · 5 citations
- DESENSITIZATION: Privacy-Aware and Attack-Preserving Crash ReportRen Ding, Hong Hu, Wen Xu, Taesoo KimNDSS 2020
- PPR: Pairwise Program ReductionMengxiao Zhang, Zhenyang Xu, Yongqiang Tian, Yu Jiang et al.FSE 2023 · 13 citations
- Static Program Reduction via Type-Directed SlicingLoi Ngo Duc Nguyen, Tahiatul Islam, Theron Wang, Sam Lenz et al.ISSTA 2025
- Manta: Hybrid-Sensitive Type Inference Toward Type-Assisted Bug Detection for Stripped BinariesChengfeng Ye, Yuandao Cai, Anshunkang Zhou, Heqing Huang et al.ASPLOS 2024 · 3 citations
