On the static analysis of indirect control transfers in binaries

Bjorn De Sutter, Bruno De Bus, Koenraad De Bosschere, P. Keyngnaert, Bart Demoen · Lirias · 2000

In this paper, we describe a method to handle uncertainty caused by indirect control transfers when reconstructing a control flow graph from a binary program. We have implemented our method on binaries for the Digital Alpha architecture, and we show that all but a few of the indirect jumps and more than 90% of the indirect procedure calls can be resolved automatically. A new analysis of relocation information almost halves the number of procedures conservatively assumed to be a possible callee of indirect calls. This new analysis has been incorporated in the Alto link-time optimizer and evaluated on the SPEC95 benchmarks. The obtained code size reduction with the new analysis is 30% on average, where it is only 23% without it.

Read the paper · More papers on PaperTik