SBridge: Identifying Source-to-Binary Function Similarity via Cross-Domain Control Block Matching
Heedong Yang, Jeongwoo Lee, Hajin Yun, Seunghoon Woo
摘要
We present SBridge, a precise approach for identifying functions in binaries that are similar to the given source code functions. Identifying reused code in binaries is critical for security, particularly for detecting propagated vulnerabilities. Although binary-to-binary comparison is feasible, leveraging source code as the reference is more practical because source code is easier to collect and analyze directly without compilation. However, significant gaps between source and binary representations, including function inlining, create challenges in cross-domain function detection. Existing approaches primarily rely on string literals or structural similarities between entire functions, failing to capture detailed code behavior and generating many false alarms. SBridge addresses these limitations through a key innovation: control block-based function matching, which encapsulates essential functional features by segmenting functions into meaningful units such as conditionals and loops. Leveraging control blocks as a cross-domain representation, SBridge enables precise measurement of function similarity between source and binary code, effectively overcoming challenges posed by function inlining and stripped binaries. For evaluation, we collected 3,904 real-world C/C++ binaries from BinKit. In experiments identifying binary functions identical to input source functions, despite approximately 40% of binary functions being inlined, SBridge achieved 75.13% recall@1 and 80.98% recall@5, outperforming existing approaches, which achieved up to 43.31% recall@1 and 50.2% recall@5. Our further analysis confirmed that SBridge effectively identifies propagated vulnerabilities in binaries.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper25
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 被引用 388 次
- Order Matters: Semantic-Aware Neural Networks for Binary Code Similarity DetectionZeping Yu, Rui Cao, Qiyi Tang, Sen Nie 等AAAI 2020 · 被引用 265 次
- jTrans: jump-aware transformer for binary code similarity detectionHao Wang, Wenjie Qu, Gilad Katz, Wenyu Zhu 等ISSTA 2022 · 被引用 139 次
- Identifying Open-Source License Violation and 1-day Security Risk at Large ScaleRuian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim 等CCS 2017 · 被引用 126 次
- BinSim: Trace-based Semantic Binary Diffing via System Call Sliced Segment Equivalence CheckingJiang Ming, Dongpeng Xu, Yufei Jiang, Dinghao WuUSENIX Security 2017 · 被引用 118 次
相关 Paper
- BINALIGNER: Aligning Binary Code for Cross-Compilation Environment DiffingYiran Zhu, Tong Tang, Jie Wan, Ziqi Yang 等NDSS 2026 · 被引用 1 次
- From Similarity Ranking to Definitive Verdict: LLM-Enhanced Source-to-Binary Function LocalizationJingyi Shi, Chengyue Liu, Zhengzi Xu, Yang Xiao 等OOPSLA 2026
- Cross-Inlining Binary Function Similarity DetectionAng Jia, Ming Fan, Xi Xu, Wuxia Jin 等ICSE 2024 · 被引用 11 次
- REVDECODE: Enhancing Binary Function Matching with Context-Aware Graph Representations and Relevance DecodingTongwei Ren, Ronghan Che, Guin Gilman, Lorenzo De Carli 等USENIX Security 2025
- Interpretation-enabled Software Reuse Detection Based on a Multi-Level Birthmark ModelXi Xu, Qinghua Zheng, Zheng Yan, Ming Fan 等ICSE 2021 · 被引用 24 次
