Hybrid Introspection for JIT-Compilers and Interpreters in Attack Surface Analysis
Pavel Mikhailovich Dovgalyuk, Vladislav Mikhailovich Stepanov, Arkadiy Ivanov, Natalia Igorevna Fursova · 2025
Finding the attack surface of the systems and applications is an important phase in secure software development lifecycle. Attack surface usually analyzed with the help of the experts or static and dynamic analysis tools. Most of the analysis tools and methods can be applied only to the single programs and do not cover the systems that consist of several heterogenous components. In this paper we present new hybrid introspection method for analyzing the software which includes interpreted code and just-in-time (JIT) compilers besides the machine code. We show how to inspect such applications when they are executed in the virtual machine. Targeting the virtual machine analysis allows one to recover the attack surface for the complex systems that include web servers, databases, and other backend components. We also present a case study with the analysis of Java application and show how to find bugs in the core dependencies, that reside on the attack surface.