4 ms·
> All of this gets easier if you can augment your static analysis with control flow traces from program executions with coverage of the relevant branches, so yo
by munin 9y ago
> All of this gets easier if you can augment your static analysis with control flow traces from program executions with coverage of the relevant branches, so you don't miss basic block entry points.
That's only true if the traces you can generate do a reasonable job at covering the states the application can find itself in, which is a big assumption.
- psykotic 9y agoYes, that's what I meant by coverage of the relevant branches. But the good news is that all these partial, heuristic sources of information can be combined. E.g. for detecting function entry points, you can combine information from ELF/PE export tables (if present), function prologues detected by a linear scan, vtables, static CALL targets, dynamic CALL targets from run-time traces, etc.