Lune

ISSTA2023Top-tier venue

OCFI: Make Function Entry Identification Hard Again

Chengbin Pang, Tiantai Zhang, Xuelan Xu, Linzhang Wang, Bing Mao

2023Year
3Citations
1Top-tier citations

Abstract

Function entry identi cation is a crucial yet challenging task for binary disassemblers that has been the focus of research in the past decades. However, recent researches show that call frame information (CFI) provides accurate and almost complete function entries. With the aid of CFI, disassemblers have signi cant improvements in function entry detection. CFI is speci cally designed for e cient stack unwinding, and every function has corresponding CFI in x64 and aarch64 architectures. Nevertheless, not every function and instruction unwinds the stack at runtime, and this observation has led to the development of techniques such as obfuscation to complicate function detection by disassemblers. We propose a prototype of ocfi to obfuscate CFI based on this observation. The goal of ocfi is to obstruct function detection of popular disassemblers that use CFI as a way to detect function entries. We evaluated ocfi on a large-scale dataset that includes real-world applications and automated generation programs, and found that the obfuscated CFI was able to correctly unwind the stack and make the detection of function entries of popular disassemblers more di cult. Furthermore, on average, ocfi incurs a size overhead of only 4% and nearly zero runtime overhead. CCS CONCEPTS • Security and privacy → Software reverse engineering; Software security engineering.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Cited by top-tier papers1

Ask how each one uses it

Builds on6

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines