BinStruct: Binary Structure Recovery Combining Static Analysis and Semantics
Yiran Zhang, Zhengzi Xu, Zhe Lang, Chengyue Liu, Yuqiang Sun, Wenbo Guo, Chengwei Liu, Weisong Sun, Yang Liu
Abstract
Binary reverse engineering is foundational to various tasks such as malware analysis and vulnerability detection. Traditional binary analysis tools mainly operate at the function level. However, modern software has grown significantly in size, with binaries often containing thousands of functions. Without understanding how these functions are organized into higher-level structures, it becomes difficult to effectively support downstream analysis tasks. Analysts must examine thousands of functions separately, making the process time-consuming and error-prone. Despite these challenges, current research on recovering the higher-level structure of binaries remains limited. To bridge this gap, we propose BinStruct, a novel binary structure recovery framework that recovers both file and module structures from binaries. BinStruct first identifies the file structure by combining data reference patterns, function calls, and semantic understanding from Large Language Models. Then, inspired by software architecture recovery in source code analysis, BinStruct identifies modules by clustering the recovered files using consensus between structural dependency and semantic similarity. Evaluation on 121 real-world stripped binaries demonstrates that BinStruct outperforms state-of-the-art techniques in both file and module recovery accuracy, while requiring only 7.42s and 34.46s on average to recover file and module structures, respectively. Case studies on Libxml2 and PredatorTheStealer demonstrate BinStruct's effectiveness on security tasks like attack surface analysis and malware investigation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2659ef1d-1bc6-450a-a789-826a670d47aeCited by top-tier papers1
Ask how each one uses itBuilds on13
- Debin: Predicting Debug Information in Stripped BinariesJingxuan He, Pesho Ivanov, Petar Tsankov, Veselin Raychev et al.CCS 2018 · 148 citations
- Patch based vulnerability matching for binary programsYifei Xu, Zhengzi Xu, Bihuan Chen, Fu Song et al.ISSTA 2020 · 74 citations
- SymLM: Predicting Function Names in Stripped Binaries via Context-Sensitive Execution-Aware Code EmbeddingsXin Jin, Kexin Pei, Jun Yeon Won, Zhiqiang LinCCS 2022 · 56 citations
- A lightweight framework for function name reassignment based on large-scale stripped binariesHan Gao, Shaoyin Cheng, Yinxing Xue, Weiming ZhangISSTA 2021 · 46 citations
- BinaryAI: Binary Software Composition Analysis via Intelligent Binary Source Code MatchingLing Jiang, Junwen An, Huihui Huang, Qiyi Tang et al.ICSE 2024 · 43 citations
Related papers
- DeLink: Source File Information Recovery in BinariesZhe Lang, Zhengzi Xu, Xiaohui Chen, Shichao Lv et al.ISSTA 2024 · 1 citation
- BinQuery: A Novel Framework for Natural Language-Based Binary Code RetrievalBolun Zhang, Zeyu Gao, Hao Wang, Yuxin Cui et al.ISSTA 2025 · 1 citation
- RecStruct: Recovering Nested Struct Types from Stripped Binaries via Stack-Driven UnificationYuxin Chen, Zhiyang Fang, Shiyi Wu, Yixin Xu et al.USENIX Security 2026
- REVDECODE: Enhancing Binary Function Matching with Context-Aware Graph Representations and Relevance DecodingTongwei Ren, Ronghan Che, Guin Gilman, Lorenzo De Carli et al.USENIX Security 2025
- Beyond Classification: Inferring Function Names in Stripped Binaries via Domain Adapted LLMsLinxi Jiang, Xin Jin, Zhiqiang LinNDSS 2025
