USENIX Security2017Top-tier venue
BinSim: Trace-based Semantic Binary Diffing via System Call Sliced Segment Equivalence Checking
Jiang Ming, Dongpeng Xu, Yufei Jiang, Dinghao Wu
Abstract
Detecting differences between two binary executables (binary diffing), first derived from patch analysis, have been widely employed in various software security analysis tasks, such as software plagiarism detection and malware lineage inference. Especially when analyzing malware variants, pervasive code obfuscation techniques have driven recent work towards determining semantic similarity in spite of ostensible difference in syntax. Existing ways rely on either comparing runtime behaviors or modeling code snippet semantics with symbolic execution. However, neither approach delivers the expected precision. In this paper, we propose system call sliced segment equivalence checking, a hybrid method to identify fine-grained semantic similarities or differences between two execution traces. We perform enhanced dynamic slicing and symbolic execution to compare the logic of instructions that impact on the observable behaviors. Our approach improves existing semantics-based binary diffing by 1) inferring whether two executable binaries' behaviors are conditionally equivalent; 2) detecting the similarities or differences, whose effects spread across multiple basic blocks. We have developed a prototype, called BinSim, and performed empirical evaluations against sophisticated obfuscation combinations and more than 1, 000 recent malware samples, including now-infamous crypto ransomware. Our experimental results show that BinSim can successfully identify finegrained relations between obfuscated binaries, and outperform existing binary diffing tools in terms of better resilience and accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 64301f2a-ab59-4cc2-bad3-0053b26a1d91Cited by top-tier papers32
- Patch based vulnerability matching for binary programsYifei Xu, Zhengzi Xu, Bihuan Chen, Fu Song et al.ISSTA 2020 · 74 citations
- Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance BoostBinlin Cheng, Jiang Ming, Jianming Fu, Guojun Peng et al.CCS 2018 · 68 citations
- VMHunt: A Verifiable Approach to Partially-Virtualized Binary Code SimplificationDongpeng Xu, Jiang Ming, Yu Fu, Dinghao WuCCS 2018 · 60 citations
- An Inside Look into the Practice of Malware AnalysisMiuyin Yong Wong, Matthew Landen, Manos Antonakakis, Douglas M. Blough et al.CCS 2021 · 58 citations
- Unleashing the hidden power of compiler optimization on binary code difference: an empirical studyXiaolei Ren, Michael Ho, Jiang Ming, Yu Lei et al.PLDI 2021 · 57 citations
Builds on2
- Cryptographic Function Detection in Obfuscated Binaries via Bit-Precise Symbolic Loop MappingDongpeng Xu, Jiang Ming, Dinghao WuS&P 2017 · 83 citations
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
Related papers
- vSim: Semantics-Aware Value Extraction for Efficient Binary Code Similarity AnalysisHuaijin Wang, Zhiqiang LinNDSS 2026 · 3 citations
- BINALIGNER: Aligning Binary Code for Cross-Compilation Environment DiffingYiran Zhu, Tong Tang, Jie Wan, Ziqi Yang et al.NDSS 2026 · 1 citation
- Revisiting Optimization-Resilience Claims in Binary Diffing Tools: Insights from LLVM Peephole Optimization AnalysisXiaolei Ren, Mengfei Ren, Yu Lei, Jiang MingFSE 2025
- Enhancing Semantic-Aware Binary Diffing with High-Confidence Dynamic Instruction AlignmentChengfeng Ye, Anshunkang Zhou, Charles ZhangNDSS 2026 · 2 citations
- DeepBinDiff: Learning Program-Wide Code Representations for Binary DiffingYue Duan, Xuezixiang Li, Jinghan Wang, Heng YinNDSS 2020
