Binary rewriting without control flow recovery
Gregory J. Duck, Xiang Gao, Abhik Roychoudhury
Abstract
Static binary rewriting has numerous applications in software security and systems-such as hardening, repair, patching, instrumentation and debugging. As such, many different static binary rewriting tools have been proposed over the decades. Since binary rewriting can insert/delete/move instructions, most existing tools attempt to recover control flow information from the input binary, and then use this information to adjust the set of jump targets in the rewritten binary. Given that the static recovery of control flow information is a hard problem in general, most existing tools use heuristics or simplifying assumptions about the input binary, such as specific compilers, source languages, etc. However, the reliance on assumptions is known to be fragile and tends not to scale in practice. For example, most existing tools cannot handle very large/complex programs such as web browsers.
In this paper we present E9Patch, a tool that can statically rewrite x86_64 binaries without any knowledge of control flow information. To do so, E9Patch develops a suite of binary rewriting methodologies, such as instruction punning and eviction, that can insert jumps to trampolines without the need to move other instructions. This preserves the set of jump targets and eliminates the need for control flow recovery and related heuristics. As such, E9Patch is robust by design, and can scale to very large (>100MB) stripped binaries including web browsers such as Google Chrome and FireFox. We also evaluate the effectiveness of E9Patch against realistic applications such as binary instrumentation, hardening and patching.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bfbc2947-874d-4d4c-aa2f-2536ea182bedCited by top-tier papers34
- StochFuzz: Sound and Cost-effective Fuzzing of Stripped Binaries by Incremental and Stochastic RewritingZhuo Zhang, Wei You, Guanhong Tao, Yousra Aafer et al.S&P 2021 · 53 citations
- Program vulnerability repair via inductive inferenceYuntong Zhang, Xiang Gao, Gregory J. Duck, Abhik RoychoudhuryISSTA 2022 · 29 citations
- SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS DriversWeiteng Chen, Yu Wang, Zheng Zhang, Zhiyun QianCCS 2021 · 25 citations
- Hopper: Interpretative Fuzzing for LibrariesPeng Chen, Yuxuan Xie, Yunlong Lyu, Yuxiao Wang et al.CCS 2023 · 23 citations
- Greybox Fuzzing for Concurrency TestingDylan Wolff, Zheng Shi, Gregory J. Duck, Umang Mathur et al.ASPLOS 2024 · 19 citations
Builds on4
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingStefan Nagy, Matthew HicksS&P 2019 · 156 citations
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 121 citations
- Superset Disassembly: Statically Rewriting x86 Binaries Without HeuristicsErick Bauman, Zhiqiang Lin, Kevin W. HamlenNDSS 2018 · 112 citations
Related papers
- Incremental CFG patching for binary rewritingXiaozhu Meng, Weijie LiuASPLOS 2021 · 8 citations
- ARMore: Pushing Love Back Into BinariesLuca Di Bartolomeo, Hossein Moghaddas, Mathias PayerUSENIX Security 2023
- Ramblr: Making Reassembly Great AgainRuoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry et al.NDSS 2017 · 155 citations
- What Cannot Be Read, Cannot Be Leveraged? Revisiting Assumptions of JIT-ROP DefensesGiorgi Maisuradze, Michael Backes, Christian RossowUSENIX Security 2016 · 41 citations
- SelectiveTaint: Efficient Data Flow Tracking With Static Binary RewritingSanchuan Chen, Zhiqiang Lin, Yinqian ZhangUSENIX Security 2021 · 45 citations
