VMHunt: A Verifiable Approach to Partially-Virtualized Binary Code Simplification
Dongpeng Xu, Jiang Ming, Yu Fu, Dinghao Wu
Abstract
Code virtualization is a highly sophisticated obfuscation technique adopted by malware authors to stay under the radar. However, the increasing complexity of code virtualization also becomes a "double-edged sword" for practical application. Due to its performance limitations and compatibility problems, code virtualization is seldom used on an entire program. Rather, it is mainly used only to safeguard the key parts of code such as security checks and encryption keys. Many techniques have been proposed to reverse engineer the virtualized code, but they share some common limitations. They assume the scope of virtualized code is known in advance and mainly focus on the classic structure of code emulator. Also, few work verifies the correctness of their deobfuscation results. In this paper, with fewer assumptions on the type and scope of code virtualization, we present a verifiable method to address the challenge of partially-virtualized binary code simplification. Our key insight is that code virtualization is a kind of process-level virtual machine (VM), and the context switch patterns when entering and exiting the VM can be used to detect the VM boundaries. Based on the scope of VM boundary, we simplify the virtualized code. We first ignore all the instructions in a given virtualized snippet that do not affect the final result of that snippet. To better revert the data obfuscation effect that encodes a variable through bitwise operations, we then run a new symbolic execution called multiple granularity symbolic execution to further simplify the trace snippet. The generated concise symbolic formulas facilitate the correctness testing of our simplification results. We have implemented our idea as an open source tool, VMHunt, and evaluated it with real-world applications and malware. The encouraging experimental results demonstrate that VMHunt is a significant improvement over the state of the art.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext df6aad7f-4a9e-41c4-87eb-e8bb3d73368cCited by top-tier papers8
- JShrink: in-depth investigation into debloating modern Java applicationsBobby R. Bruce, Tianyi Zhang, Jaspreet Arora, Guoqing Harry Xu et al.FSE 2020 · 46 citations
- Where's Crypto?: Automated Identification and Classification of Proprietary Cryptographic Primitives in Binary CodeCarlo Meijer, Veelasha Moonsamy, Jos WetzelsUSENIX Security 2021 · 26 citations
- A Wolf in Sheep's Clothing: Practical Black-box Adversarial Attacks for Evading Learning-based Windows Malware Detection in the WildXiang Ling, Zhiyu Wu, Bin Wang, Wei Deng et al.USENIX Security 2024 · 13 citations
- Parema: an unpacking framework for demystifying VM-based Android packersLei Xue, Yuxiao Yan, Luyi Yan, Muhui Jiang et al.ISSTA 2021 · 11 citations
- LibvDiff: Library Version Difference Guided OSS Version Identification in BinariesChaopeng Dong, Siyuan Li, Shouguo Yang, Yang Xiao et al.ICSE 2024 · 9 citations
Builds on7
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- BinSim: Trace-based Semantic Binary Diffing via System Call Sliced Segment Equivalence CheckingJiang Ming, Dongpeng Xu, Yufei Jiang, Dinghao WuUSENIX Security 2017 · 118 citations
- Syntia: Synthesizing the Semantics of Obfuscated CodeTim Blazytko, Moritz Contag, Cornelius Aschermann, Thorsten HolzUSENIX Security 2017 · 99 citations
- Cryptographic Function Detection in Obfuscated Binaries via Bit-Precise Symbolic Loop MappingDongpeng Xu, Jiang Ming, Dinghao WuS&P 2017 · 83 citations
- Backward-Bounded DSE: Targeting Infeasibility Questions on Obfuscated CodesSébastien Bardin, Robin David, Jean-Yves MarionS&P 2017 · 63 citations
Related papers
- Inspecting Virtual Machine Diversification Inside Virtualization ObfuscationNaiqian Zhang, Dongpeng Xu, Jiang Ming, Jun Xu et al.S&P 2025
- Chosen-Instruction Attack Against Commercial Code Virtualization ObfuscatorsShijia Li, Chunfu Jia, Pengda Qiu, Qiyuan Chen et al.NDSS 2022
- VAHunt: Warding Off New Repackaged Android Malware in App-Virtualization's ClothingLuman Shi, Jiang Ming, Jianming Fu, Guojun Peng et al.CCS 2020 · 24 citations
- Augmenting Search-based Program Synthesis with Local Inference Rules to Improve Black-box DeobfuscationVidal Attias, Nicolas Bellec, Grégoire Menguy, Sébastien Bardin et al.CCS 2025
- Forced Execution for Malware Protected by Commercial Virtualization ObfuscatorsYifei Zhan, Yukun Cui, Shuofeng Hao, Dongnan He et al.CCS 2026
