ARMore: Pushing Love Back Into Binaries
Luca Di Bartolomeo, Hossein Moghaddas, Mathias Payer
摘要
Static rewriting enables late-state code changes (e.g., to add mitigations, to remove unnecessary code, or to instrument for code coverage) at low overhead in security-critical environments. Most research on static rewriting has so far focused on the x86 architecture. However, the prevalence and proliferation of ARM-based devices along with a large amount of personal data (e.g., health and sensor data) that they process calls for efficient introspection and analysis capabilities on the ARM platform. Addressing the unique challenges on aarch64, we introduce ARMore, the first efficient, robust, and heuristicfree static binary rewriter for arbitrary aarch64 binaries that produces reassembleable assembly. The key improvements introduced by ARMore make the recovery of indirect control flow an option rather than a necessity. Instead of crashing, the cost of an uncovered target only causes the small overhead of an additional branch. ARMore can rewrite binaries from different languages and compilers (even arbitrary hand-written assembly), both on PIC and non-PIC code, with or without symbols, including exception handling for C++ and Go binaries, and also including binaries with mixed data and text. ARMore is sound as it does not rely on any assumptions about the input binary. ARMore is also efficient: it does not employ any expensive dynamic translation techniques, incurring negligible overhead (<1% in our evaluated benchmarks). Our AFL++ coverage instrumentation pass enables fuzzing of closed-source aarch64 binaries at three times the speed compared to the stateof-the-art (AFL-QEMU), and we found 58 unique crashes in closed-source software. ARMore is the only static rewriter whose rewritten binaries correctly pass all SQLite3 and coreutils test cases and autopkgtest of 97.5% Debian packages. adrp x0, 0xab0000 add x1, x0, 0x100 ; built pointer 0xab100 ldr x2, [x0, 0x200] ; built pointer 0xab200 add x0, x0, 0x80 ; built pointer 0xab080 Listing 1: Multiple pointers built from one adrp instruction. adrp x0, 0xab0000 mov x1, x0 add x1, x1, 0x100 ; built pointer 0xab0100 Listing 2: Changing register during pointer construction.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- PANIC: PAN-assisted Intra-process Memory Isolation on ARMJiali Xu, Mengyao Xie, Chenggang Wu, Yinqian Zhang 等CCS 2023 · 被引用 11 次
- Trapped by Your WORDs: (Ab)using Processor Exception for Generic Binary Instrumentation on Bare-metal Embedded DevicesShipei Qu, Xiaolin Zhang, Chi Zhang, Dawu GuDAC 2024 · 被引用 3 次
- Towards Sound Reassembly of Modern x86-64 BinariesHyungseok Kim, Soomin Kim, Sang Kil ChaASPLOS 2025 · 被引用 3 次
- LeanBin: Harnessing Lifting and Recompilation to Debloat BinariesIgor Wodiany, Antoniu Pop, Mikel LujánASE 2024 · 被引用 1 次
- Disassembly as Weighted Interval Scheduling with Learned WeightsAntonio Flores-Montoya, Junghee Lim, Adam Seitz, Akshay Sood 等S&P 2025
它引用的顶会 Paper13
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 被引用 187 次
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez 等USENIX Security 2019 · 被引用 168 次
- Ramblr: Making Reassembly Great AgainRuoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry 等NDSS 2017 · 被引用 155 次
- Superset Disassembly: Statically Rewriting x86 Binaries Without HeuristicsErick Bauman, Zhiqiang Lin, Kevin W. HamlenNDSS 2018 · 被引用 112 次
相关 Paper
- Binary rewriting without control flow recoveryGregory J. Duck, Xiang Gao, Abhik RoychoudhuryPLDI 2020 · 被引用 77 次
- Egalito: Layout-Agnostic Binary RecompilationDavid Williams-King, Hidenori Kobayashi, Kent Williams-King, Graham Patterson 等ASPLOS 2020 · 被引用 68 次
- StochFuzz: Sound and Cost-effective Fuzzing of Stripped Binaries by Incremental and Stochastic RewritingZhuo Zhang, Wei You, Guanhong Tao, Yousra Aafer 等S&P 2021 · 被引用 53 次
- Incremental CFG patching for binary rewritingXiaozhu Meng, Weijie LiuASPLOS 2021 · 被引用 8 次
- Datalog DisassemblyAntonio Flores-Montoya, Eric M. SchulteUSENIX Security 2020
