MAKO: Refining Indirect-Call Targets with Type Relation Unfolding
Yibo Jin, Wei Chen, Bowen Zhang, Charles Zhang
Abstract
Type-based indirect call resolution scales well to large software systems, but type information it uses can lead to a proliferation of infeasible callees and thus compromise precision. Existing precision-enhancing schemes resort to reasoning about reachability between indirect calls and functions to directly remove spurious callees. However, they suffer from insufficient precision or severe performance overhead due to their limited reasoning capabilities.<br/><br/>In this work, we argue that existing approaches overlook the importance of type relations in refining indirect-call targets, and refocus on their validity to eliminate spurious callees within the steps of type-based resolution. To facilitate precise and scalable reduction of invalid type relations, we unfold global type relations to their producer statements and verify their validity for each indirect call via syntax-level reachability between their associated statements and the call itself. With these refined type relations, type-based resolution effectively blocks numerous resolution traces leading to spurious callees while imposing slight overhead. We implemented our approach as Mako, and evaluations demonstrate that it serves as a practical resolver by achieving the best precision across most benchmark programs without any performance breakdowns, thanks to a 59.5% reduction in type relations used for resolving indirect calls and an 80.9% reduction in indirect-call targets with an average process time of 373 seconds. Notably, when supporting value-flow-based bug detection, Mako reduces the reported warnings spanning indirect calls by 19.2%, with acceptable time costs in common industrial settings.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get dfd66f95-e680-4439-a3e3-42e3edae38a0Related papers
- Improving Indirect-Call Analysis in LLVM with Type and Data-Flow Co-AnalysisDinghao Liu, Shouling Ji, Kangjie Lu, Qinming HeUSENIX Security 2024 · 13 citations
- Unleashing the Power of Type-Based Call Graph Construction by Using Regional Pointer InformationYuandao Cai, Yibo Jin, Charles ZhangUSENIX Security 2024 · 16 citations
- Redefining Indirect Call Analysis with KallGraphGuoren Li, Manu Sridharan, Zhiyun QianS&P 2025
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 142 citations
- DEEPTYPE: Refining Indirect Call Targets with Strong Multi-layer Type AnalysisTianrou Xia, Hong Hu, Dinghao WuUSENIX Security 2024 · 13 citations
