Redefining Indirect Call Analysis with KallGraph
Guoren Li, Manu Sridharan, Zhiyun Qian
摘要
Call graph construction is a crucial prerequisite for a wide range of static analysis applications. State-of-the-art methods minimize precise but expensive pointer tracking by falling back to so-called “type analysis” which scales well to large programs such as the Linux kernel. In this paper, we undertake an in-depth evaluation and analysis of type-based methods that reveal new insights into flaws due to their adhoc nature. First, we find that in a number of cases, the soundness claims of recent type-based methods do not hold, resulting in missing indirect call targets. Second, we find the analysis is overly conservative in multiple aspects, leading to a large number of false indirect call targets. Based on these insights, we make the observation that such type-based methods can be converted into a hybrid pointer analysis framework that unifies the traditional pointer tracking methods and type-based methods. Based on such a framework, we develop a practical indirect call analysis that addresses both soundness and precision limitations. Our results demonstrate a remarkable level of soundness and precision improvements. KallGraph simultaneously improves precision and soundness by pruning up to 90% of indirect call targets and eliminating hundreds to thousands of missed indirect calls. Finally, KallGraph is fully parallelizable and can complete the analysis of Linux kernels in times ranging from tens of minutes to a few hours.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Towards More Accurate Static Analysis for Taint-Style Bug Detection in Linux KernelHaonan Li, Hang Zhang, Kexin Pei, Zhiyun QianASE 2025 · 被引用 5 次
- SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow IntegrityZhechang Zhang, Hengkai Ye, Song Liu, Hong HuNDSS 2026 · 被引用 1 次
- PAGENT: Program Analysis Guided LLM Agent for Proof-of-Concept GenerationAchintya Desai, Md Shafiuzzaman, Wenbo Guo, Tevfik BultanISSTA 2026
它引用的顶会 Paper30
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 被引用 142 次
- DR. CHECKER: A Soundy Analysis for Linux Kernel DriversAravind Machiry, Chad Spensky, Jake Corina, Nick Stephens 等USENIX Security 2017 · 被引用 126 次
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung 等USENIX Security 2019 · 被引用 77 次
- Origin-sensitive Control Flow IntegrityMustakimur Khandaker, Wenqing Liu, Abu Naser, Zhi Wang 等USENIX Security 2019 · 被引用 71 次
- GREBE: Unveiling Exploitation Potential for Linux Kernel BugsZhenpeng Lin, Yueqi Chen, Yuhang Wu, Dongliang Mu 等S&P 2022 · 被引用 47 次
相关 Paper
- Improving Indirect-Call Analysis in LLVM with Type and Data-Flow Co-AnalysisDinghao Liu, Shouling Ji, Kangjie Lu, Qinming HeUSENIX Security 2024 · 被引用 13 次
- Unleashing the Power of Type-Based Call Graph Construction by Using Regional Pointer InformationYuandao Cai, Yibo Jin, Charles ZhangUSENIX Security 2024 · 被引用 16 次
- GNNIC: Finding Long-Lost Sibling Functions with Abstract SimilarityQiushi Wu, Zhongshu Gu, Hani Jamjoom, Kangjie LuNDSS 2024
- Striking a Balance: Pruning False-Positives from Static Call GraphsAkshay Utture, Shuyang Liu, Christian Gram Kalhauge, Jens PalsbergICSE 2022 · 被引用 18 次
- DEEPTYPE: Refining Indirect Call Targets with Strong Multi-layer Type AnalysisTianrou Xia, Hong Hu, Dinghao WuUSENIX Security 2024 · 被引用 13 次
