Using Logic Programming to Recover C++ Classes and Methods from Compiled Executables
Edward J. Schwartz, Cory F. Cohen, Michael Duggan, Jeffrey Gennari, Jeffrey S. Havrilla, Charles Hines
摘要
High-level C++ source code abstractions such as classes and methods greatly assist human analysts and automated algorithms alike when analyzing C++ programs. Unfortunately, these abstractions are lost when compiling C++ source code, which impedes the understanding of C++ executables. In this paper, we propose a system, OOAnalyzer, that uses an innovative new design to statically recover detailed C++ abstractions from executables in a scalable manner. OOAnalyzer's design is motivated by the observation that many human analysts reason about C++ programs by recognizing simple patterns in binary code and then combining these findings using logical inference, domain knowledge, and intuition. We codify this approach by combining a lightweight symbolic analysis with a flexible Prolog-based reasoning system. Unlike most existing work, OO-Analyzer is able to recover both polymorphic and non-polymorphic C++ classes. We show in our evaluation that OOAnalyzer assigns over 78% of methods to the correct class on our test corpus, which includes both malware and real-world software such as Firefox and MySQL. These recovered abstractions can help analysts understand the behavior of C++ malware and cleanware, and can also improve the precision of program analyses on C++ executables. CCS CONCEPTS • Security and privacy → Software reverse engineering; Malware and its mitigation;
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper21
- Elipmoc: advanced decompilation of Ethereum smart contractsNeville Grech, Sifis Lagouvardos, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2022 · 被引用 40 次
- ReSym: Harnessing LLMs to Recover Variable and Data Structure Symbols from Stripped BinariesDanning Xie, Zhuo Zhang, Nan Jiang, Xiangzhe Xu 等CCS 2024 · 被引用 21 次
- TYGR: Type Inference on Stripped Binaries using Graph Neural NetworksChang Zhu, Ziyang Li, Anton Xue, Ati Priya Bajaj 等USENIX Security 2024 · 被引用 10 次
- FunProbe: Probing Functions from Binary Code through Probabilistic AnalysisSoomin Kim, Hyungseok Kim, Sang Kil ChaFSE 2023 · 被引用 8 次
- Precise Static Identification of Ethereum Storage VariablesSifis Lagouvardos, Yannis Bollanos, Michael Debono, Neville Grech 等ICSE 2026 · 被引用 2 次
它引用的顶会 Paper2
相关 Paper
- CLASScanner: Efficient C++ Class Recovery from Binaries Driven by Object Flow GraphsJiaming Wang, Gongming Wang, Songtao Yang, Xi Cao 等ISSTA 2026
- BinStruct: Binary Structure Recovery Combining Static Analysis and SemanticsYiran Zhang, Zhengzi Xu, Zhe Lang, Chengyue Liu 等ASE 2025
- Augmenting Decompiler Output with Learned Variable Names and TypesQibin Chen, Jeremy Lacomis, Edward J. Schwartz, Claire Le Goues 等USENIX Security 2022
- PyAnalyzer: An Effective and Practical Approach for Dependency Extraction from Python CodeWuxia Jin, Shuo Xu, Dawei Chen, Jiajun He 等ICSE 2024 · 被引用 4 次
- Identifying Java calls in native code via binary scanningGeorge Fourtounis, Leonidas Triantafyllou, Yannis SmaragdakisISSTA 2020 · 被引用 23 次
