When Function Signature Recovery Meets Compiler Optimization
Yan Lin, Debin Gao
Abstract
Matching indirect function callees and callers using function signatures recovered from binary executables (number of arguments and argument types) has been proposed to construct a more fine-grained control-flow graph (CFG) to help control-flow integrity (CFI) enforcement. However, various compiler optimizations may violate calling conventions and result in unmatched function signatures. In this paper, we present eight scenarios in which compiler optimizations impact function signature recovery, and report experimental results with 1,344 real-world applications of various optimization levels. Most interestingly, our experiments show that compiler optimizations have both positive and negative impacts on function signature recovery, e.g., its elimination of redundant instructions at callers makes counting of the number of arguments more accurate, while it hurts argument type matching as the compiler chooses the most efficient (but potentially different) types at callees and callers. To better deal with these compiler optimizations, we propose a set of improved policies and report our more accurate CFG models constructed from the 1,344 applications. We additionally compare our results recovered from binary executables with those extracted from program source and reveal scenarios where compiler optimization makes the task of accurate function signature recovery undecidable.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e7f0962e-1f73-4cf8-bb9a-cda893493694Cited by top-tier papers8
- StateFormer: fine-grained type recovery from binaries using generative state modelingKexin Pei, Jonas Guan, Matthew Broughton, Zhongtian Chen et al.FSE 2021 · 53 citations
- TypeSqueezer: When Static Recovery of Function Signatures for Binary Executables Meets Dynamic AnalysisZiyi Lin, Jinku Li, Bowen Li, Haoyu Ma et al.CCS 2023 · 7 citations
- When Compiler Optimizations Meet Symbolic Execution: An Empirical StudyYue Zhang, Melih Sirlanci, Ruoyu Wang, Zhiqiang LinCCS 2024 · 2 citations
- Cornucopia : A Framework for Feedback Guided Generation of BinariesVidush Singhal, Akul Abhilash Pillai, Charitha Saumya, Milind Kulkarni et al.ASE 2022 · 2 citations
- Binary Cryptographic Function Identification via Similarity Analysis with Path-Insensitive EmulationYikun Hu, Yituo He, Wenyu He, Haoran Li et al.OOPSLA 2025 · 2 citations
Related papers
- Applying System Call Filtering to Real-World Binaries (Experience Paper)Soumyakant Priyadarshan, Seyedhamed GhavamniaISSTA 2026 · 1 citation
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski et al.S&P 2016 · 227 citations
- Improving Indirect-Call Analysis in LLVM with Type and Data-Flow Co-AnalysisDinghao Liu, Shouling Ji, Kangjie Lu, Qinming HeUSENIX Security 2024 · 13 citations
- Finding Cracks in Shields: On the Security of Control Flow Integrity MechanismsYuan Li, Mingzhe Wang, Chao Zhang, Xingman Chen et al.CCS 2020 · 32 citations
- Refining Indirect Call Targets at the Binary LevelSun Hyoung Kim, Cong Sun, Dongrui Zeng, Gang TanNDSS 2021
