0Pricing
Reverse Engineering & Binary Analysis Basics · บทเรียน

การวิเคราะห์กราฟลำดับการทำงาน

ทำความเข้าใจและตีความกราฟลำดับการทำงาน (CFG) เพื่อแสดงเส้นทางและตรรกะการทำงานของโปรแกรมเป็นภาพ

การวิเคราะห์กราฟลำดับการทำงาน เป็นบทเรียน Reverse Engineering & Binary Analysis Basics ฟรีบน CoddyKit นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Reverse Engineering & Binary Analysis Basics และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Reverse Engineering & Binary Analysis Basics มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

Intro to Control Flow Graphs

Welcome! In this lesson, we'll dive into Control Flow Graphs (CFGs). A CFG is like a roadmap for your program, visually showing all possible execution paths.

It's a crucial tool in reverse engineering because it helps you understand a program's logic without actually running it.

The Building Blocks: Basic Blocks

At the heart of a CFG are basic blocks. Think of a basic block as a straight line of instructions.

  • It's a sequence of code with only one entry point (the first instruction).
  • It has only one exit point (the last instruction).
  • There are no jumps or jump targets anywhere in between.

For example, A = 10; B = A + 5; C = B * 2; could be a single basic block.

Edges Show the Way

Edges in a CFG connect basic blocks, showing how execution can flow from one block to another. These represent jumps, calls, or fall-throughs.

  • Unconditional Edges: Always taken, like a direct jump to the next block.
  • Conditional Edges: Taken only if a certain condition is met, leading to different paths (e.g., an IF statement).

A Simple Program's Flow

Let's look at a very simple C program. Its CFG would mostly consist of sequential basic blocks, one after another.

Try running this example:

#include <stdio.h>

int main() {
  int x = 5;
  int y = 10;
  int sum = x + y;
  printf("Sum: %d\n", sum);
  return 0;
}

Conditional Logic (If/Else)

Conditional statements like if/else create branches in a CFG. A basic block containing a conditional jump will have two outgoing edges.

One edge represents the 'true' path, and the other represents the 'false' path. These paths usually merge back together later.

#include <stdio.h>

int main() {
  int age = 20;
  if (age >= 18) {
    printf("Adult\n");
  } else {
    printf("Minor\n");
  }
  return 0;
}

Loop Structures (For/While)

Loops, such as for or while, are easily identifiable in a CFG by a special type of edge called a back-edge.

A back-edge points from a block inside the loop back to an earlier block, creating a cycle. This cycle represents the repeated execution of the loop body.

#include <stdio.h>

int main() {
  for (int i = 0; i < 3; i++) {
    printf("Iteration %d\n", i);
  }
  return 0;
}

Function Calls in CFGs

When your program calls a function, the CFG represents this too. An edge will typically lead from the caller's basic block to the entry point of the called function's own CFG.

Once the function finishes, execution returns to the caller, usually to the next instruction after the call.

#include <stdio.h>

void greet() {
  printf("Hello from greet!\n");
}

int main() {
  printf("Calling greet...\n");
  greet();
  printf("Greet returned.\n");
  return 0;
}

The Power of CFGs in RE

CFGs are incredibly powerful for reverse engineering:

  • Understand Logic: Quickly grasp complex decision-making and overall program flow.
  • Identify Functions: See distinct subgraphs representing different functions.
  • Find Vulnerabilities: Spot unusual paths, unreachable code, or logic flaws.
  • Trace Execution: Predict potential execution paths without needing to run the program.

Navigating CFGs in Disassemblers

Industry-standard tools like Ghidra and IDA Pro automatically generate and display CFGs for you. They allow you to:

  • Visually inspect basic blocks and their connecting edges.
  • Click on blocks to view the assembly instructions they contain.
  • Follow edges to trace the program's execution flow logically.

This visual aid simplifies understanding complex binaries significantly.

CFG Quick Check

Consider a simple program that includes both an if/else statement and a for loop. Think about how these structures are represented in a Control Flow Graph.

Recap: Your CFG Toolbox

Great job! You've learned the fundamentals of Control Flow Graphs:

  • CFGs are visual maps of program execution paths.
  • They consist of basic blocks (sequential instruction groups) and edges (showing flow).
  • CFGs clearly show conditional logic (if/else) and loops (with back-edges).
  • These graphs are indispensable for understanding program logic during reverse engineering, especially when using tools like Ghidra or IDA Pro.

คำถามที่พบบ่อย

บทเรียน “การวิเคราะห์กราฟลำดับการทำงาน” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “การวิเคราะห์กราฟลำดับการทำงาน” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Reverse Engineering & Binary Analysis Basics ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Reverse Engineering & Binary Analysis Basics มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “การวิเคราะห์กราฟลำดับการทำงาน”

ทำความเข้าใจและตีความกราฟลำดับการทำงาน (CFG) เพื่อแสดงเส้นทางและตรรกะการทำงานของโปรแกรมเป็นภาพ คุณปฏิบัติ Reverse Engineering & Binary Analysis Basics ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Reverse Engineering & Binary Analysis Basics หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Reverse Engineering & Binary Analysis Basics บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน

บทเรียน “การวิเคราะห์กราฟลำดับการทำงาน” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Reverse Engineering & Binary Analysis Basics นี้ได้ไหม

ได้ บทเรียน Reverse Engineering & Binary Analysis Basics ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. บทนำสู่เครื่องแยกส่วนคำสั่ง
  2. การระบุฟังก์ชันและข้อมูล
  3. การวิเคราะห์กราฟลำดับการทำงาน
  4. การวิเคราะห์สตริงและการอ้างอิงข้าม
← กลับไปที่ Reverse Engineering & Binary Analysis Basics