0Pricing
Reverse Engineering & Binary Analysis Basics · レッスン

制御フローグラフ解析

制御フローグラフ(CFG)を理解して解釈し、プログラムの実行経路とロジックを可視化します。

「制御フローグラフ解析」はCoddyKit上の無料Reverse Engineering & Binary Analysis Basicsレッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはReverse Engineering & Binary Analysis Basics学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Reverse Engineering & Binary Analysis Basicsコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Intro to Control Flow Graphs

Welcome! In this lesson, we'll dive into Control Flow Graphs (CFGs). A CFG is like a roadmap for your program, visually showing all possible execution paths.

It's a crucial tool in reverse engineering because it helps you understand a program's logic without actually running it.

The Building Blocks: Basic Blocks

At the heart of a CFG are basic blocks. Think of a basic block as a straight line of instructions.

  • It's a sequence of code with only one entry point (the first instruction).
  • It has only one exit point (the last instruction).
  • There are no jumps or jump targets anywhere in between.

For example, A = 10; B = A + 5; C = B * 2; could be a single basic block.

Edges Show the Way

Edges in a CFG connect basic blocks, showing how execution can flow from one block to another. These represent jumps, calls, or fall-throughs.

  • Unconditional Edges: Always taken, like a direct jump to the next block.
  • Conditional Edges: Taken only if a certain condition is met, leading to different paths (e.g., an IF statement).

A Simple Program's Flow

Let's look at a very simple C program. Its CFG would mostly consist of sequential basic blocks, one after another.

Try running this example:

#include <stdio.h>

int main() {
  int x = 5;
  int y = 10;
  int sum = x + y;
  printf("Sum: %d\n", sum);
  return 0;
}

Conditional Logic (If/Else)

Conditional statements like if/else create branches in a CFG. A basic block containing a conditional jump will have two outgoing edges.

One edge represents the 'true' path, and the other represents the 'false' path. These paths usually merge back together later.

#include <stdio.h>

int main() {
  int age = 20;
  if (age >= 18) {
    printf("Adult\n");
  } else {
    printf("Minor\n");
  }
  return 0;
}

Loop Structures (For/While)

Loops, such as for or while, are easily identifiable in a CFG by a special type of edge called a back-edge.

A back-edge points from a block inside the loop back to an earlier block, creating a cycle. This cycle represents the repeated execution of the loop body.

#include <stdio.h>

int main() {
  for (int i = 0; i < 3; i++) {
    printf("Iteration %d\n", i);
  }
  return 0;
}

Function Calls in CFGs

When your program calls a function, the CFG represents this too. An edge will typically lead from the caller's basic block to the entry point of the called function's own CFG.

Once the function finishes, execution returns to the caller, usually to the next instruction after the call.

#include <stdio.h>

void greet() {
  printf("Hello from greet!\n");
}

int main() {
  printf("Calling greet...\n");
  greet();
  printf("Greet returned.\n");
  return 0;
}

The Power of CFGs in RE

CFGs are incredibly powerful for reverse engineering:

  • Understand Logic: Quickly grasp complex decision-making and overall program flow.
  • Identify Functions: See distinct subgraphs representing different functions.
  • Find Vulnerabilities: Spot unusual paths, unreachable code, or logic flaws.
  • Trace Execution: Predict potential execution paths without needing to run the program.

Navigating CFGs in Disassemblers

Industry-standard tools like Ghidra and IDA Pro automatically generate and display CFGs for you. They allow you to:

  • Visually inspect basic blocks and their connecting edges.
  • Click on blocks to view the assembly instructions they contain.
  • Follow edges to trace the program's execution flow logically.

This visual aid simplifies understanding complex binaries significantly.

CFG Quick Check

Consider a simple program that includes both an if/else statement and a for loop. Think about how these structures are represented in a Control Flow Graph.

Recap: Your CFG Toolbox

Great job! You've learned the fundamentals of Control Flow Graphs:

  • CFGs are visual maps of program execution paths.
  • They consist of basic blocks (sequential instruction groups) and edges (showing flow).
  • CFGs clearly show conditional logic (if/else) and loops (with back-edges).
  • These graphs are indispensable for understanding program logic during reverse engineering, especially when using tools like Ghidra or IDA Pro.

よくある質問

「制御フローグラフ解析」レッスンは無料ですか?

はい。「制御フローグラフ解析」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Reverse Engineering & Binary Analysis Basicsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Reverse Engineering & Binary Analysis Basicsコースには全4レッスンが含まれています。

「制御フローグラフ解析」で何を学びますか?

制御フローグラフ(CFG)を理解して解釈し、プログラムの実行経路とロジックを可視化します。 ブラウザで直接実行するハンズオンコードでReverse Engineering & Binary Analysis Basicsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Reverse Engineering & Binary Analysis Basicsを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのReverse Engineering & Binary Analysis Basicsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。

「制御フローグラフ解析」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このReverse Engineering & Binary Analysis Basicsレッスンでコードを書いて実行できますか?

はい。すべてのReverse Engineering & Binary Analysis Basicsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. 逆アセンブラ入門
  2. 関数とデータの特定
  3. 制御フローグラフ解析
  4. 文字列とクロスリファレンス分析
← Reverse Engineering & Binary Analysis Basicsに戻る