USENIX Security2023Top-tier venue
ARMore: Pushing Love Back Into Binaries
Luca Di Bartolomeo, Hossein Moghaddas, Mathias Payer
Abstract
Static rewriting enables late-state code changes (e.g., to add mitigations, to remove unnecessary code, or to instrument for code coverage) at low overhead in security-critical environments. Most research on static rewriting has so far focused on the x86 architecture. However, the prevalence and proliferation of ARM-based devices along with a large amount of personal data (e.g., health and sensor data) that they process calls for efficient introspection and analysis capabilities on the ARM platform. Addressing the unique challenges on aarch64, we introduce ARMore, the first efficient, robust, and heuristicfree static binary rewriter for arbitrary aarch64 binaries that produces reassembleable assembly. The key improvements introduced by ARMore make the recovery of indirect control flow an option rather than a necessity. Instead of crashing, the cost of an uncovered target only causes the small overhead of an additional branch. ARMore can rewrite binaries from different languages and compilers (even arbitrary hand-written assembly), both on PIC and non-PIC code, with or without symbols, including exception handling for C++ and Go binaries, and also including binaries with mixed data and text. ARMore is sound as it does not rely on any assumptions about the input binary. ARMore is also efficient: it does not employ any expensive dynamic translation techniques, incurring negligible overhead (<1% in our evaluated benchmarks). Our AFL++ coverage instrumentation pass enables fuzzing of closed-source aarch64 binaries at three times the speed compared to the stateof-the-art (AFL-QEMU), and we found 58 unique crashes in closed-source software. ARMore is the only static rewriter whose rewritten binaries correctly pass all SQLite3 and coreutils test cases and autopkgtest of 97.5% Debian packages. adrp x0, 0xab0000 add x1, x0, 0x100 ; built pointer 0xab100 ldr x2, [x0, 0x200] ; built pointer 0xab200 add x0, x0, 0x80 ; built pointer 0xab080 Listing 1: Multiple pointers built from one adrp instruction. adrp x0, 0xab0000 mov x1, x0 add x1, x1, 0x100 ; built pointer 0xab0100 Listing 2: Changing register during pointer construction.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f72aa15f-15ea-40f0-8e9c-b5f0392aa22aCited by top-tier papers9
- PANIC: PAN-assisted Intra-process Memory Isolation on ARMJiali Xu, Mengyao Xie, Chenggang Wu, Yinqian Zhang et al.CCS 2023 · 11 citations
- Trapped by Your WORDs: (Ab)using Processor Exception for Generic Binary Instrumentation on Bare-metal Embedded DevicesShipei Qu, Xiaolin Zhang, Chi Zhang, Dawu GuDAC 2024 · 3 citations
- Towards Sound Reassembly of Modern x86-64 BinariesHyungseok Kim, Soomin Kim, Sang Kil ChaASPLOS 2025 · 3 citations
- LeanBin: Harnessing Lifting and Recompilation to Debloat BinariesIgor Wodiany, Antoniu Pop, Mikel LujánASE 2024 · 1 citation
- Disassembly as Weighted Interval Scheduling with Learned WeightsAntonio Flores-Montoya, Junghee Lim, Adam Seitz, Akshay Sood et al.S&P 2025
Builds on13
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez et al.USENIX Security 2019 · 168 citations
- Ramblr: Making Reassembly Great AgainRuoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry et al.NDSS 2017 · 155 citations
- Superset Disassembly: Statically Rewriting x86 Binaries Without HeuristicsErick Bauman, Zhiqiang Lin, Kevin W. HamlenNDSS 2018 · 112 citations
Related papers
- Binary rewriting without control flow recoveryGregory J. Duck, Xiang Gao, Abhik RoychoudhuryPLDI 2020 · 77 citations
- Egalito: Layout-Agnostic Binary RecompilationDavid Williams-King, Hidenori Kobayashi, Kent Williams-King, Graham Patterson et al.ASPLOS 2020 · 68 citations
- StochFuzz: Sound and Cost-effective Fuzzing of Stripped Binaries by Incremental and Stochastic RewritingZhuo Zhang, Wei You, Guanhong Tao, Yousra Aafer et al.S&P 2021 · 53 citations
- Incremental CFG patching for binary rewritingXiaozhu Meng, Weijie LiuASPLOS 2021 · 8 citations
- Datalog DisassemblyAntonio Flores-Montoya, Eric M. SchulteUSENIX Security 2020
