Automatic Functions Annotations through Concrete Procedural Debugging and ELF Libification

Jonathan Brossard · 2025

In this article, we present a novel approach to program analysis through selective concrete execution. While static analysis of ELF binaries is necessarily limited by the theoretical undecidability of control-flow and data-flow analysis algorithms, we detail a new approach to reverse engineering through selective concrete execution of arbitrary functions within a x86_64 GNU/Linux binary by transforming ELF applications into shared libraries. This approach, named "procedural debugging", allows us to empirically recover information about function parameters and return values without resorting to any disassembly or decompilation, which are undecidable in general. In turn, this dynamic approach may be used as a feedback loop into existing program analyzers, being them static, fuzzing, symbolic, or concolic, to enrich their understanding of application interfaces. We publish an open-source framework, named the Witchcraft Compiler Collection, under a permissive MIT/BSD license, implementing binary libification, procedural debugging, and automatic function prototype annotations with the hope of benefiting the security community.

Read the paper · More papers on PaperTik