{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:00:27Z","timestamp":1781283627688,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","funder":[{"name":"National Science Foundation","award":["CNS-2243632"],"award-info":[{"award-number":["CNS-2243632"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,23]]},"DOI":"10.1145\/3800506.3803514","type":"proceedings-article","created":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:24:42Z","timestamp":1781281482000},"page":"269-282","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["BinType: Type based Indirect Call Target Refinement on Binary Programs"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-3001-3885","authenticated-orcid":false,"given":"Sun Hyoung","family":"Kim","sequence":"first","affiliation":[{"name":"Rebellions Inc, Seongnam-si, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0032-2571","authenticated-orcid":false,"given":"Dongrui","family":"Zeng","sequence":"additional","affiliation":[{"name":"Palo Alto Networks, Inc., State College, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6219-6545","authenticated-orcid":false,"given":"Monika","family":"Santra","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, State College, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6109-6091","authenticated-orcid":false,"given":"Gang","family":"Tan","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, State College, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"12th ACM Conference on Computer and Communications Security (CCS). 340-353","author":"Abadi Mart\u00edn","year":"2005","unstructured":"Mart\u00edn Abadi, Mihai Budiu, \u00dalfar Erlingsson, and Jay Ligatti. 2005. Control-flow integrity. In 12th ACM Conference on Computer and Communications Security (CCS). 340-353."},{"key":"e_1_3_2_1_2_1","unstructured":"National Security Agency. 2017. Ghidra Reverse Engineering Tool. https:\/\/www.nsa.gov\/resources\/everyone\/ghidra\/."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24723-4_2"},{"key":"e_1_3_2_1_4_1","volume-title":"International Static Analysis Symposium. 84-104","author":"Balatsouras George","year":"2016","unstructured":"George Balatsouras and Yannis Smaragdakis. 2016. Structure-sensitive points-to analysis for C and C. In International Static Analysis Symposium. 84-104."},{"key":"e_1_3_2_1_5_1","volume-title":"ACM Conference on Object-Oriented Programming, Systems, Languages, and Applications (OOPSLA). 243-262","author":"Bravenboer Martin","year":"2009","unstructured":"Martin Bravenboer and Yannis Smaragdakis. 2009. Strictly declarative specification of sophisticated points-to analyses. In ACM Conference on Object-Oriented Programming, Systems, Languages, and Applications (OOPSLA). 243-262."},{"key":"e_1_3_2_1_6_1","volume-title":"Schwartz","author":"Brumley David","year":"2011","unstructured":"David Brumley, Ivan Jager, Thanassis Avgerinos, and Edward J. Schwartz. 2011. BAP: A Binary Analysis Platform. In Computer Aided Verification (CAV). 463-469."},{"key":"e_1_3_2_1_7_1","volume-title":"Control-Flow Bending: On the Effectiveness of Control-Flow Integrity. In 24th Usenix Security Symposium. 161-176","author":"Carlini Nicholas","unstructured":"Nicholas Carlini, Antonio Barresi, Mathias Payer, David Wagner, and Thomas R. Gross. 2015. Control-Flow Bending: On the Effectiveness of Control-Flow Integrity. In 24th Usenix Security Symposium. 161-176."},{"key":"e_1_3_2_1_8_1","unstructured":"David Dewey and Jonathon T Giffin. 2012. Static detection of C vtable escape vulnerabilities in binary code.. In NDSS."},{"key":"e_1_3_2_1_9_1","volume-title":"Control Jujutsu: On the Weaknesses of Fine-Grained Control Flow Integrity. In 22nd ACM Conference on Computer and Communications Security (CCS). 901-913","author":"Evans Issac","year":"2015","unstructured":"Issac Evans, Fan Long, Ulziibayar Otgonbaatar, Howard Shrobe, Martin Rinard, Hamed Okhravi, and Stelios Sidiroglou-Douskos. 2015. Control Jujutsu: On the Weaknesses of Fine-Grained Control Flow Integrity. In 22nd ACM Conference on Computer and Communications Security (CCS). 901-913."},{"key":"e_1_3_2_1_10_1","volume-title":"On the Effectiveness of Type-based Control Flow Integrity. In Annual Computer Security Applications Conference. 28-39","author":"Farkhani Reza Mirzazade","year":"2018","unstructured":"Reza Mirzazade Farkhani, Saman Jafari, Sajjad Arshad, William Robertson, Engin Kirda, and Hamed Okhravi. 2018. On the Effectiveness of Type-based Control Flow Integrity. In Annual Computer Security Applications Conference. 28-39."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489273"},{"key":"e_1_3_2_1_12_1","volume-title":"Fine-Grained Control-Flow Integrity for Kernel Software. In IEEE European Symposium on Security and Privacy (EuroS&P). 179-194","author":"Ge Xinyang","year":"2016","unstructured":"Xinyang Ge, Nirupama Talele, Mathias Payer, and Trent Jaeger. 2016. Fine-Grained Control-Flow Integrity for Kernel Software. In IEEE European Symposium on Security and Privacy (EuroS&P). 179-194."},{"key":"e_1_3_2_1_13_1","first-page":"1","volume-title":"Proceedings of the ACM on Programming Languages","volume":"1","author":"Grech Neville","year":"2017","unstructured":"Neville Grech and Yannis Smaragdakis. 2017. P\/Taint: unified points-to and taint analysis. Proceedings of the ACM on Programming Languages, Vol. 1, OOPSLA (2017), 1-28."},{"key":"e_1_3_2_1_14_1","unstructured":"Hex-Rays. 2008. The IDA Pro disassembler and debugger. https:\/\/www.hex-rays.com\/products\/ida\/."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-41540-6_23"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2499370.2462191"},{"key":"e_1_3_2_1_17_1","volume-title":"28th Usenix Security Symposium. 195-211","author":"Khandaker Mustakimur Rahman","year":"2019","unstructured":"Mustakimur Rahman Khandaker, Wenqing Liu, Abu Naser, Zhi Wang, and Jie Yang. 2019. Origin-sensitive control flow integrity. In 28th Usenix Security Symposium. 195-211."},{"key":"e_1_3_2_1_18_1","volume-title":"Network and Distributed System Security Symposium (NDSS).","author":"Kim Sun Hyoung","year":"2021","unstructured":"Sun Hyoung Kim, Cong Sun, Dongrui Zeng, and Gang Tan. 2021. Refining Indirect Call Targets at the Binary Level. In Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3497776.3517776"},{"key":"e_1_3_2_1_20_1","volume-title":"TIE: Principled reverse engineering of types in binary programs.","author":"Lee JongHyup","year":"2011","unstructured":"JongHyup Lee, Thanassis Avgerinos, and David Brumley. 2011. TIE: Principled reverse engineering of types in binary programs. (2011)."},{"key":"e_1_3_2_1_21_1","volume-title":"Redefining Indirect Call Analysis with KallGraph. In 2025 IEEE Symposium on Security and Privacy (SP). IEEE, 2957-2975","author":"Li Guoren","year":"2025","unstructured":"Guoren Li, Manu Sridharan, and Zhiyun Qian. 2025. Redefining Indirect Call Analysis with KallGraph. In 2025 IEEE Symposium on Security and Privacy (SP). IEEE, 2957-2975."},{"key":"e_1_3_2_1_22_1","volume-title":"2021 IEEE Symposium on Security and Privacy (SP). IEEE, 36-52","author":"Lin Yan","year":"2021","unstructured":"Yan Lin and Debin Gao. 2021. When function signature recovery meets compiler optimization. In 2021 IEEE Symposium on Security and Privacy (SP). IEEE, 36-52."},{"key":"e_1_3_2_1_23_1","volume-title":"Refining Indirect-Call Targets with Multi-Layer Type Analysis. In 26th ACM Conference on Computer and Communications Security (CCS). 1867-1881","author":"Lu Kangjie","year":"2019","unstructured":"Kangjie Lu and Hong Hu. 2019. Where Does It Go? Refining Indirect-Call Targets with Multi-Layer Type Analysis. In 26th ACM Conference on Computer and Communications Security (CCS). 1867-1881."},{"key":"e_1_3_2_1_24_1","first-page":"190","article-title":"Pin: building customized program analysis tools with dynamic instrumentation","author":"Luk Chi-Keung","year":"2005","unstructured":"Chi-Keung Luk, Robert Cohn, Robert Muth, Harish Patil, Artur Klauser, Geoffrey Lowney, Steven Wallace, Vijay Janapa Reddi, and Kim Hazelwood. 2005. Pin: building customized program analysis tools with dynamic instrumentation. In Programming Language Design and Implementation (PLDI). 190-200.","journal-title":"Programming Language Design and Implementation (PLDI)."},{"key":"e_1_3_2_1_25_1","first-page":"288","volume-title":"DIMVA 2019, Gothenburg, Sweden, June 19-20, 2019, Proceedings 16","author":"Maier Alwin","year":"2019","unstructured":"Alwin Maier, Hugo Gascon, Christian Wressnegger, and Konrad Rieck. 2019. Typeminer: Recovering types in binary programs using machine learning. In Detection of Intrusions and Malware, and Vulnerability Assessment: 16th International Conference, DIMVA 2019, Gothenburg, Sweden, June 19-20, 2019, Proceedings 16. Springer, 288-308."},{"key":"e_1_3_2_1_26_1","first-page":"395","article-title":"RockSalt: Better, Faster, Stronger SFI for the x86","author":"Morrisett Greg","year":"2012","unstructured":"Greg Morrisett, Gang Tan, Joseph Tassarotti, Jean-Baptiste Tristan, and Edward Gan. 2012. RockSalt: Better, Faster, Stronger SFI for the x86. In Programming Language Design and Implementation (PLDI). 395-404.","journal-title":"Programming Language Design and Implementation (PLDI)."},{"key":"e_1_3_2_1_27_1","volume-title":"International Symposium on Research in Attacks, Intrusions and Defenses (RAID). 423-444","author":"Muntean Paul","year":"2018","unstructured":"Paul Muntean, Matthias Fischer, Gang Tan, Zhiqiang Lin, Jens Grossklags, and Claudia Eckert. 2018. tauCFI: Type-Assisted Control Flow Integrity for x86-64 Binaries. In International Symposium on Research in Attacks, Intrusions and Defenses (RAID). 423-444."},{"key":"e_1_3_2_1_28_1","volume-title":"2019 28th International Conference on Parallel Architectures and Compilation Techniques (PACT). IEEE, 82-96","author":"Nappa Patrick","year":"2019","unstructured":"Patrick Nappa, David Zhao, Pavle Suboti\u0107, and Bernhard Scholz. 2019. Fast parallel equivalence relations in a Datalog compiler. In 2019 28th International Conference on Parallel Architectures and Compilation Techniques (PACT). IEEE, 82-96."},{"key":"e_1_3_2_1_29_1","volume-title":"Modular Control-Flow Integrity. In ACM Conference on Programming Language Design and Implementation (PLDI). 577-587","author":"Niu Ben","year":"2014","unstructured":"Ben Niu and Gang Tan. 2014. Modular Control-Flow Integrity. In ACM Conference on Programming Language Design and Implementation (PLDI). 577-587."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468607"},{"key":"e_1_3_2_1_31_1","volume-title":"Scheduled Execution-Based Binary Indirect Call Targets Refinement. In European Symposium on Research in Computer Security. Springer, 3-23","author":"Shi Yangyang","year":"2024","unstructured":"Yangyang Shi, Linan Tian, Liwei Chen, Yanqi Yang, and Gang Shi. 2024. Scheduled Execution-Based Binary Indirect Call Targets Refinement. In European Symposium on Research in Computer Security. Springer, 3-23."},{"key":"e_1_3_2_1_32_1","volume-title":"IEEE Symposium on Security and Privacy (S&P). 138-157","author":"Shoshitaishvili Yan","year":"2016","unstructured":"Yan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens, Mario Polino, Andrew Dutcher, John Grosen, Siji Feng, Christophe Hauser, Christopher Kruegel, et al., 2016. SoK:(state of) the art of war: Offensive techniques in binary analysis. In IEEE Symposium on Security and Privacy (S&P). 138-157."},{"key":"e_1_3_2_1_33_1","first-page":"485","article-title":"Introspective analysis: context-sensitivity, across the board","author":"Smaragdakis Yannis","year":"2014","unstructured":"Yannis Smaragdakis, George Kastrinis, and George Balatsouras. 2014. Introspective analysis: context-sensitivity, across the board. In Programming Language Design and Implementation (PLDI). 485-495.","journal-title":"Programming Language Design and Implementation (PLDI)."},{"key":"e_1_3_2_1_34_1","volume-title":"Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM. In 23rd Usenix Security Symposium.","author":"Tice Caroline","year":"2014","unstructured":"Caroline Tice, Tom Roeder, Peter Collingbourne, Stephen Checkoway, \u00dalfar Erlingsson, Luis Lozano, and Geoff Pike. 2014. Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM. In 23rd Usenix Security Symposium."},{"key":"e_1_3_2_1_35_1","volume-title":"24th ACM Conference on Computer and Communications Security (CCS). 1675-1689","author":"van der Veen Victor","year":"2017","unstructured":"Victor van der Veen, Dennis Andriesse, Manolis Stamatogiannakis, Xi Chen, Herbert Bos, and Cristiano Giuffrdia. 2017. The dynamics of innocent flesh on the bone: Code reuse ten years later. In 24th ACM Conference on Computer and Communications Security (CCS). 1675-1689."},{"key":"e_1_3_2_1_36_1","volume-title":"IEEE Symposium on Security and Privacy (S&P). 934-953","author":"Der Veen Victor Van","year":"2016","unstructured":"Victor Van Der Veen, Enes G\u00f6ktas, Moritz Contag, Andre Pawoloski, Xi Chen, Sanjay Rawat, Herbert Bos, Thorsten Holz, Elias Athanasopoulos, and Cristiano Giuffrida. 2016. A tough call: Mitigating advanced code-reuse attacks at the binary level. In IEEE Symposium on Security and Privacy (S&P). 934-953."},{"key":"e_1_3_2_1_37_1","first-page":"5877","volume-title":"DEEPTYPE: Refining Indirect Call Targets with Strong Multi-layer Type Analysis. In 33rd USENIX Security Symposium (USENIX Security 24)","author":"Xia Tianrou","year":"2024","unstructured":"Tianrou Xia, Hong Hu, and Dinghao Wu. 2024. DEEPTYPE: Refining Indirect Call Targets with Strong Multi-layer Type Analysis. In 33rd USENIX Security Symposium (USENIX Security 24). 5877-5894."},{"key":"e_1_3_2_1_38_1","volume-title":"8th ACM Conference on Data and Application Security and Privacy (CODASPY). 366-376","author":"Zeng Dongrui","year":"2018","unstructured":"Dongrui Zeng and Gang Tan. 2018. From Debugging-Information Based Binary-Level Type Inference to CFG Generation. In 8th ACM Conference on Data and Application Security and Privacy (CODASPY). 366-376."},{"key":"e_1_3_2_1_39_1","volume-title":"Zhaofeng Chen, and Dawn Song.","author":"Zhang Chao","year":"2015","unstructured":"Chao Zhang, Chengyu Song, Kevin Zhijie Chen, Zhaofeng Chen, and Dawn Song. 2015. VTint: Protecting Virtual Function Tables' Integrity.. In NDSS."},{"key":"e_1_3_2_1_40_1","volume-title":"Control Flow Integrity for COTS Binaries. In 22nd Usenix Security Symposium. 337-352","author":"Zhang Mingwei","unstructured":"Mingwei Zhang and R. Sekar. 2013. Control Flow Integrity for COTS Binaries. In 22nd Usenix Security Symposium. 337-352."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00051"},{"key":"e_1_3_2_1_42_1","volume-title":"2023 IEEE Symposium on Security and Privacy (SP). IEEE, 2357-2374","author":"Zhu Wenyu","year":"2023","unstructured":"Wenyu Zhu, Zhiyao Feng, Zihan Zhang, Jianjun Chen, Zhijian Ou, Min Yang, and Chao Zhang. 2023. Callee: Recovering call graphs for binaries with transfer and contrastive learning. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE, 2357-2374."}],"event":{"name":"CODASPY '26: Sixteenth ACM Conference on Data and Application Security and Privacy","location":"Frankfurt am Main Germany","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Sixteenth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"deposited":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:28:59Z","timestamp":1781281739000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3800506.3803514"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":42,"alternative-id":["10.1145\/3800506.3803514","10.1145\/3800506"],"URL":"https:\/\/doi.org\/10.1145\/3800506.3803514","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"2026-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}