A Hybrid Analysis-Based Construction Method for Tainted Control Flow Graphs of Binary Programs

Honggang Xie, Xiangdong Li, Zenghui Shen · 2025

In recent years, control flow graphs (CFGs) have gained increasing prominence in binary vulnerability detection due to their comprehensive representation of a program's execution paths. However, traditional methods for constructing CFGs often encounter significant challenges, such as limited precision in static analysis and high runtime overhead in dynamic analysis. To address these limitations, this paper proposes a novel hybrid approach that combines static taint analysis with dynamic symbolic execution to construct precise and efficient taint control flow graphs. The proposed methodology begins with static taint analysis to propagate tainted data across the program, offering details of potential taint paths. Dynamic Symbol Execution refines the analysis by combining the results of static taint analysis with setting response times, parsing runtime behavior, and exploring possible execution paths in more detail. By integrating the strengths of both techniques, our approach effectively reduces false positives and captures complex runtime behaviors that static analysis alone cannot handle. Experimental evaluations on real-world binaries demonstrate the efficacy of the proposed approach, showcasing significant improvements in CFG precision, runtime efficiency, and vulnerability detection capabilities. This work contributes to advancing binary analysis techniques and provides a robust tool for enhancing program security.

Read the paper · More papers on PaperTik