Sign inSign up

tanishs26/xrayflow

By tanishs26

•Updated 6 months ago

A high-performance static analysis engine written in Rust for detecting memory corruption

Image
Security
0

141

tanishs26/xrayflow repository overview

⁠XrayFlow — Advanced Static Analysis Engine for C/C++

XrayFlow is a high-performance static analysis engine written in Rust for detecting memory corruption and input-driven vulnerabilities in C/C++ codebases.

Unlike traditional SAST tools that rely heavily on pattern matching, xrayflow performs program analysis and multi-stage validation to identify vulnerabilities with higher confidence and reduced false positives.


⁠Overview

XrayFlow combines detection, validation, and prioritization into a single pipeline:

  • Detection using interprocedural taint analysis and dataflow tracking
  • Validation using control-flow, constraints, and dominance analysis
  • Ranking using exploitability scoring and RBOM (Risk Bill of Materials)

This approach allows XrayFlow to distinguish between theoretical issues and practically exploitable vulnerabilities.


⁠Key Capabilities

⁠Detection Engine
  • Interprocedural taint tracking (source to sink)
  • Pointer and alias analysis
  • Function pointer resolution
  • Call graph construction
  • Dataflow propagation across functions and variables

⁠Validation Engine

Each detected finding is validated using multiple techniques:

⁠1. Taint-Based Validation

Confirms dataflow from untrusted sources (e.g., argv, getenv, read) to sensitive sinks.

⁠2. Structural Validation

Identifies unsafe API usage such as:

  • sprintf, strcpy, strcat
  • memcpy, memset
  • gets and similar unbounded operations
⁠3. State-Based Validation

Tracks memory lifecycle to validate:

  • Use-after-free
  • Double free
⁠4. Feasible Path Analysis

Uses constraint-aware control flow traversal:

  • Supports conditions like pointer nullability and flags
  • Eliminates logically impossible execution paths
⁠5. Dominance Analysis

Performs CFG-based dominator analysis:

  • Confirms guaranteed execution order (e.g., free dominates use)
  • Enables classification of definite vulnerabilities

⁠Confidence Model

Each finding is assigned a confidence level:

ConfidenceDescription
HIGHGuaranteed vulnerability (validated via dominance or equivalent certainty)
MEDIUMFeasible execution path exists
LOWWeak or uncertain signal

This model allows teams to focus on high-impact, high-confidence issues first.


⁠Supported Vulnerability Classes

  • Buffer overflow (including pointer arithmetic)
  • Use-after-free
  • Double free
  • Format string vulnerabilities
  • Command injection

⁠Output Formats

XrayFlow supports multiple output formats for different workflows:

  • Table (default, human-readable)
  • JSON (machine-readable)
  • Markdown report
  • SARIF (for GitHub Security and CI/CD integration)
  • Summary (compact overview)

⁠Docker Usage

⁠Scan Current Directory
docker run --rm -v $(pwd):/scan tanishs26/xrayflow:latest --table /scan
⁠Scan a Specific Directory
docker run --rm -v /path/to/code:/scan tanishs26/xrayflow:latest --table /scan
⁠Show Only High-Confidence Findings
docker run --rm -v /path/to/code:/scan tanishs26/xrayflow:latest \
  --min-confidence high --show-path /scan
⁠Generate SARIF Output
docker run --rm -v $(pwd):/scan tanishs26/xrayflow:latest \
  --sarif /scan > results.sarif

⁠CLI Options

--json                 Emit JSON output
--summary              Emit compact summary
--table                Emit human-readable table (default)
--report               Emit Markdown report
--sarif                Emit SARIF output

--baseline <file>      Compare against baseline JSON
--language <lang>      Force language (javascript | c | cpp)

--validated-only       Show only validated findings
--min-confidence       low | medium | high
--show-path            Show validated execution path
--show-notes           Show validation reasoning

--sort-by-exploitability
--top <N>
--debug-validator      Enable validator debugging output

⁠Example Output

RBOM: score=89 grade=C findings=41 exploitability=MEDIUM

HIGH  HIGH  HIGH  c.buffer_overflow.pointer_arithmetic
Path: sprintf@file:line
Exploitability: HIGH (80)

⁠Architecture

sast-c          C/C++ analysis engine
sast-js         JavaScript analysis engine (experimental)
sast-validator  multi-stage validation engine
rbom            risk scoring and prioritization
xrayflow        command-line interface
sast-api        REST API (in development)

⁠Version Highlights (v1.0)

  • Added dominance-aware validation using CFG dominator analysis
  • Implemented feasible-path validation with constraint tracking
  • Introduced multi-mode validation (taint, structural, state, path, dominance)
  • Improved confidence scoring and filtering
  • Added SARIF output for integration with GitHub Security
  • Reduced false positives through path feasibility and validation layering

⁠Use Cases

  • Bug bounty research
  • Kernel and driver security auditing
  • CI/CD security scanning pipelines
  • Secure code review workflows
  • Vulnerability triage and prioritisation

⁠Author

Tanish (tanishs26)


⁠Notes

XrayFlow is designed to balance detection coverage with validation accuracy. It prioritises actionable findings over exhaustive but noisy output.

Tag summary

Content type

Image

Digest

sha256:adbbf6c66…

Size

31.2 MB

Last updated

6 months ago

docker pull tanishs26/xrayflow:1.0