Lune

ISSTA2023顶会

OCFI: Make Function Entry Identification Hard Again

Chengbin Pang, Tiantai Zhang, Xuelan Xu, Linzhang Wang, Bing Mao

2023年份
3被引次数
1顶会引用

摘要

Function entry identi cation is a crucial yet challenging task for binary disassemblers that has been the focus of research in the past decades. However, recent researches show that call frame information (CFI) provides accurate and almost complete function entries. With the aid of CFI, disassemblers have signi cant improvements in function entry detection. CFI is speci cally designed for e cient stack unwinding, and every function has corresponding CFI in x64 and aarch64 architectures. Nevertheless, not every function and instruction unwinds the stack at runtime, and this observation has led to the development of techniques such as obfuscation to complicate function detection by disassemblers. We propose a prototype of ocfi to obfuscate CFI based on this observation. The goal of ocfi is to obstruct function detection of popular disassemblers that use CFI as a way to detect function entries. We evaluated ocfi on a large-scale dataset that includes real-world applications and automated generation programs, and found that the obfuscated CFI was able to correctly unwind the stack and make the detection of function entries of popular disassemblers more di cult. Furthermore, on average, ocfi incurs a size overhead of only 4% and nearly zero runtime overhead. CCS CONCEPTS • Security and privacy → Software reverse engineering; Software security engineering.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

它引用的顶会 Paper6

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖