Devil is Virtual: Reversing Virtual Inheritance in C++ Binaries
Rukayat Ayomide Erinfolami, Aravind Prakash
摘要
The complexities that arise from the implementation of object-oriented concepts in C++ such as virtual dispatch and dynamic type casting have attracted the attention of attackers and defenders alike. Binary-level defenses are dependent on full and precise recovery of class inheritance tree of a given program. While current solutions focus on recovering single and multiple inheritances from the binary, they are oblivious of virtual inheritance. The conventional wisdom among binary-level defenses is that virtual inheritance is uncommon and/or support for single and multiple inheritances provides implicit support for virtual inheritance. In this paper, we show neither to be true. Specifically, (1) we present an efficient technique to detect virtual inheritance in C++ binaries and show through a study that virtual inheritance can be found in non-negligible number (more than 10% on Linux and 12.5% on Windows) of real-world C++ programs including Mysql and Libstdc++. (2) We show that failure to handle virtual inheritance introduces both false positives and false negatives in the hierarchy tree. These falses either introduce attack surface when the hierarchy recovered is used to enforce CFI policies, or make the hierarchy difficult to understand when it is needed for program understanding (e.g., during decompilation). (3) We present a solution to recover virtual inheritance from COTS binaries. We recover a maximum of 95% and 95.5% (GCC -O0) and a minimum of 77.5% and 73.8% (Clang -O2) of virtual and intermediate bases respectively in the virtual inheritance tree.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- TIPS: Tracking Integer-Pointer Value Flows for C++ Member Function PointersChangwei Zou, Dongjie He, Yulei Sui, Jingling XueFSE 2024 · 被引用 1 次
- BaseMirror: Automatic Reverse Engineering of Baseband Commands from Android's Radio Interface LayerWenqiang Li, Haohuang Wen, Zhiqiang LinCCS 2024 · 被引用 1 次
- Augmenting Decompiler Output with Learned Variable Names and TypesQibin Chen, Jeremy Lacomis, Edward J. Schwartz, Claire Le Goues 等USENIX Security 2022
- Egg Hunt in Tesla Infotainment: A First Look at Reverse Engineering of Qt BinariesHaohuang Wen, Zhiqiang LinUSENIX Security 2023
- COMRace: Detecting Data Race Vulnerabilities in COM ObjectsFangming Gu, Qingli Guo, Lian Li, Zhiniang Peng 等USENIX Security 2022
它引用的顶会 Paper6
- Neural Nets Can Learn Function Type Signatures From BinariesZheng Leong Chua, Shiqi Shen, Prateek Saxena, Zhenkai LiangUSENIX Security 2017 · 被引用 175 次
- Ramblr: Making Reassembly Great AgainRuoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry 等NDSS 2017 · 被引用 155 次
- Superset Disassembly: Statically Rewriting x86 Binaries Without HeuristicsErick Bauman, Zhiqiang Lin, Kevin W. HamlenNDSS 2018 · 被引用 112 次
- VTrust: Regaining Trust on Virtual CallsChao Zhang, Dawn Song, Scott A. Carr, Mathias Payer 等NDSS 2016 · 被引用 91 次
- Using Logic Programming to Recover C++ Classes and Methods from Compiled ExecutablesEdward J. Schwartz, Cory F. Cohen, Michael Duggan, Jeffrey Gennari 等CCS 2018 · 被引用 53 次
相关 Paper
- MARX: Uncovering Class Hierarchies in C++ ProgramsAndre Pawlowski, Moritz Contag, Victor van der Veen, Chris Ouwehand 等NDSS 2017 · 被引用 45 次
- Protecting C++ Dynamic Dispatch Through VTable InterleavingDimitar Bounov, Rami Gökhan Kici, Sorin LernerNDSS 2016 · 被引用 77 次
- TypeSqueezer: When Static Recovery of Function Signatures for Binary Executables Meets Dynamic AnalysisZiyi Lin, Jinku Li, Bowen Li, Haoyu Ma 等CCS 2023 · 被引用 7 次
- CLASScanner: Efficient C++ Class Recovery from Binaries Driven by Object Flow GraphsJiaming Wang, Gongming Wang, Songtao Yang, Xi Cao 等ISSTA 2026
- VScape: Assessing and Escaping Virtual Call ProtectionsKaixiang Chen, Chao Zhang, Tingting Yin, Xingman Chen 等USENIX Security 2021 · 被引用 5 次
