RTrace: Towards Better Visibility of Shared Library Execution
Huaifeng Zhang, Ahmed Ali-Eldin
摘要
Software supply chain security has become a critical concern in recent years. Modern software systems increasingly depend on third-party dependencies to accelerate development. Shared libraries are the prevalent form of software sharing and hence, of third-party dependencies in modern software systems. As more attacks target the software supply chain, understanding the behavior of these dependencies is essential for identifying vulnerabilities and malicious code. Hence, accurately tracing function calls within shared libraries is critical for effective software security analysis. However, existing library function tracers often fail to meet this need. As we show in this work, state-of-the-art library function tracers are limited in effectiveness and scalability, missing a significant number of function calls and failing with more complex workloads, resulting in incomplete or misleading views of runtime behavior. In this paper, we present RTrace, a tracing tool designed to address the limitations of existing solutions. We analyze the root causes of why widely used tracers miss function calls and identify common pitfalls such as relying on incorrect symbol information and inability to monitor early or indirect function invocations. RTrace overcomes these challenges by incorporating comprehensive runtime monitoring, function boundary detection, and support for implicit and unconventional function calls. We compare RTrace to four state-of-the-art tracers, namely, emphltrace, emphdrltrace, emphldaudit, and emphIntelPT. Our evaluation across 21 applications and 92 shared libraries shows that RTrace significantly outperforms existing tools in detecting function call. RTrace achieves an F1-score of at least 0.92 on all benchmarks, whereas the best existing tracer reaches only 0.74, providing more accurate visibility into shared library runtime behavior. Finally, we show how RTrace can be used to assist in detecting malicious package and in vulnerability analysis by providing a more complete view of shared library function usage.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung 等USENIX Security 2019 · 被引用 132 次
- DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge MappingCheng Huang, Nannan Wang, Ziyan Wang, Siqi Sun 等USENIX Security 2024 · 被引用 38 次
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood 等USENIX Security 2024 · 被引用 16 次
- A Needle is an Outlier in a Haystack: Hunting Malicious PyPI Packages with Code ClusteringWentao Liang, Xiang Ling, Jingzheng Wu, Tianyue Luo 等ASE 2023 · 被引用 15 次
相关 Paper
- VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability AnalysisYutao Hu, Chaofan Li, Yueming Wu, Yifeng Cai 等NDSS 2026 · 被引用 1 次
- Magneto: A Step-Wise Approach to Exploit Vulnerabilities in Dependent Libraries via LLM-Empowered Directed FuzzingZhuotong Zhou, Yongzhuo Yang, Susheng Wu, Yiheng Huang 等ASE 2024 · 被引用 7 次
- From Noise to Signal: Precisely Identify Affected Packages of Known Vulnerabilities in npm EcosystemYingyuan Pu, Lingyun Ying, Yacong GuNDSS 2026 · 被引用 4 次
- Understanding the Limitations of C/C++ Binary Third-Party Library Detection Tool: An Empirical Study at ScaleChengyue Liu, Zhengzi Xu, Kaixuan Li, Jiahui Wu 等FSE 2026
- ProgSCA: Software Composition Analysis via Program-Level ModelingPeihong Li, Cheng Li, Yuchen Gu, Yanzhe Hu 等ISSTA 2026
