Binary rewriting without control flow recovery
Gregory J. Duck, Xiang Gao, Abhik Roychoudhury
摘要
Static binary rewriting has numerous applications in software security and systems-such as hardening, repair, patching, instrumentation and debugging. As such, many different static binary rewriting tools have been proposed over the decades. Since binary rewriting can insert/delete/move instructions, most existing tools attempt to recover control flow information from the input binary, and then use this information to adjust the set of jump targets in the rewritten binary. Given that the static recovery of control flow information is a hard problem in general, most existing tools use heuristics or simplifying assumptions about the input binary, such as specific compilers, source languages, etc. However, the reliance on assumptions is known to be fragile and tends not to scale in practice. For example, most existing tools cannot handle very large/complex programs such as web browsers.
In this paper we present E9Patch, a tool that can statically rewrite x86_64 binaries without any knowledge of control flow information. To do so, E9Patch develops a suite of binary rewriting methodologies, such as instruction punning and eviction, that can insert jumps to trampolines without the need to move other instructions. This preserves the set of jump targets and eliminates the need for control flow recovery and related heuristics. As such, E9Patch is robust by design, and can scale to very large (>100MB) stripped binaries including web browsers such as Google Chrome and FireFox. We also evaluate the effectiveness of E9Patch against realistic applications such as binary instrumentation, hardening and patching.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper34
- StochFuzz: Sound and Cost-effective Fuzzing of Stripped Binaries by Incremental and Stochastic RewritingZhuo Zhang, Wei You, Guanhong Tao, Yousra Aafer 等S&P 2021 · 被引用 53 次
- Program vulnerability repair via inductive inferenceYuntong Zhang, Xiang Gao, Gregory J. Duck, Abhik RoychoudhuryISSTA 2022 · 被引用 29 次
- SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS DriversWeiteng Chen, Yu Wang, Zheng Zhang, Zhiyun QianCCS 2021 · 被引用 25 次
- Hopper: Interpretative Fuzzing for LibrariesPeng Chen, Yuxuan Xie, Yunlong Lyu, Yuxiao Wang 等CCS 2023 · 被引用 23 次
- Greybox Fuzzing for Concurrency TestingDylan Wolff, Zheng Shi, Gregory J. Duck, Umang Mathur 等ASPLOS 2024 · 被引用 19 次
它引用的顶会 Paper4
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 被引用 187 次
- Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingStefan Nagy, Matthew HicksS&P 2019 · 被引用 156 次
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 被引用 121 次
- Superset Disassembly: Statically Rewriting x86 Binaries Without HeuristicsErick Bauman, Zhiqiang Lin, Kevin W. HamlenNDSS 2018 · 被引用 112 次
相关 Paper
- Incremental CFG patching for binary rewritingXiaozhu Meng, Weijie LiuASPLOS 2021 · 被引用 8 次
- ARMore: Pushing Love Back Into BinariesLuca Di Bartolomeo, Hossein Moghaddas, Mathias PayerUSENIX Security 2023
- Ramblr: Making Reassembly Great AgainRuoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry 等NDSS 2017 · 被引用 155 次
- What Cannot Be Read, Cannot Be Leveraged? Revisiting Assumptions of JIT-ROP DefensesGiorgi Maisuradze, Michael Backes, Christian RossowUSENIX Security 2016 · 被引用 41 次
- SelectiveTaint: Efficient Data Flow Tracking With Static Binary RewritingSanchuan Chen, Zhiqiang Lin, Yinqian ZhangUSENIX Security 2021 · 被引用 45 次
