Using Logic Programming to Recover C++ Classes and Methods from Compiled Executables
Edward J. Schwartz, Cory F. Cohen, Michael Duggan, Jeffrey Gennari, Jeffrey S. Havrilla, Charles Hines
Abstract
High-level C++ source code abstractions such as classes and methods greatly assist human analysts and automated algorithms alike when analyzing C++ programs. Unfortunately, these abstractions are lost when compiling C++ source code, which impedes the understanding of C++ executables. In this paper, we propose a system, OOAnalyzer, that uses an innovative new design to statically recover detailed C++ abstractions from executables in a scalable manner. OOAnalyzer's design is motivated by the observation that many human analysts reason about C++ programs by recognizing simple patterns in binary code and then combining these findings using logical inference, domain knowledge, and intuition. We codify this approach by combining a lightweight symbolic analysis with a flexible Prolog-based reasoning system. Unlike most existing work, OO-Analyzer is able to recover both polymorphic and non-polymorphic C++ classes. We show in our evaluation that OOAnalyzer assigns over 78% of methods to the correct class on our test corpus, which includes both malware and real-world software such as Firefox and MySQL. These recovered abstractions can help analysts understand the behavior of C++ malware and cleanware, and can also improve the precision of program analyses on C++ executables. CCS CONCEPTS • Security and privacy → Software reverse engineering; Malware and its mitigation;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bf3ef0f3-bc63-4059-b320-d7692f974d81Cited by top-tier papers21
- Elipmoc: advanced decompilation of Ethereum smart contractsNeville Grech, Sifis Lagouvardos, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2022 · 40 citations
- ReSym: Harnessing LLMs to Recover Variable and Data Structure Symbols from Stripped BinariesDanning Xie, Zhuo Zhang, Nan Jiang, Xiangzhe Xu et al.CCS 2024 · 21 citations
- TYGR: Type Inference on Stripped Binaries using Graph Neural NetworksChang Zhu, Ziyang Li, Anton Xue, Ati Priya Bajaj et al.USENIX Security 2024 · 10 citations
- FunProbe: Probing Functions from Binary Code through Probabilistic AnalysisSoomin Kim, Hyungseok Kim, Sang Kil ChaFSE 2023 · 8 citations
- Precise Static Identification of Ethereum Storage VariablesSifis Lagouvardos, Yannis Bollanos, Michael Debono, Neville Grech et al.ICSE 2026 · 2 citations
Builds on2
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski et al.S&P 2016 · 227 citations
- MARX: Uncovering Class Hierarchies in C++ ProgramsAndre Pawlowski, Moritz Contag, Victor van der Veen, Chris Ouwehand et al.NDSS 2017 · 45 citations
Related papers
- CLASScanner: Efficient C++ Class Recovery from Binaries Driven by Object Flow GraphsJiaming Wang, Gongming Wang, Songtao Yang, Xi Cao et al.ISSTA 2026
- BinStruct: Binary Structure Recovery Combining Static Analysis and SemanticsYiran Zhang, Zhengzi Xu, Zhe Lang, Chengyue Liu et al.ASE 2025
- Augmenting Decompiler Output with Learned Variable Names and TypesQibin Chen, Jeremy Lacomis, Edward J. Schwartz, Claire Le Goues et al.USENIX Security 2022
- PyAnalyzer: An Effective and Practical Approach for Dependency Extraction from Python CodeWuxia Jin, Shuo Xu, Dawei Chen, Jiajun He et al.ICSE 2024 · 4 citations
- Identifying Java calls in native code via binary scanningGeorge Fourtounis, Leonidas Triantafyllou, Yannis SmaragdakisISSTA 2020 · 23 citations
