arrow
返回

Enhancing DNN-Based Binary Code Function Search With Low-Cost Equivalence Checking

delete2023-01-01
delete7
PRE
AI
H
Huaijin Wang
P
Pingchuan Ma
袁渊源 封面图
袁渊源 (Yuanyuan Yuan)
Z
Zhibo Liu
S
Shuai Wang *
Q
Qiyi Tang
S
Sen Nie
S
Shi Wu
DOI:10.1109/TSE.2022.3149240delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Binary & nbsp;code function search has been used as the core basis of various security and software engineering applications, including malware clustering, code clone detection, and vulnerability audits. Recognizing logically similar assembly functions, however, remains a challenge. Most binary code search tools rely on program structure-level information, such as control flow and data flow graphs, that is extracted using program analysis techniques or deep neural networks (DNNs). However, DNN-based techniques capture lexical-, control structure-, or data flow-level information of binary code for representation learning, which is often too coarse-grained and does not accurately denote program functionality. Additionally, it may exhibit low robustness to a variety of challenging settings, such as compiler optimizations and obfuscations. This paper proposes a general solution for enhancing the top-k ranked candidates in DNN-based binary code function search. The key idea is to design a low-cost and comprehensive equivalence check that quickly exposes functionality deviations between the target function and its top-k matched functions. Functions that fail this equivalence check can be shaved from the top-k list, and functions that pass the check can be revisited to move ahead on the top-k ranked candidates, in a deliberate way. We design a practical and efficient equivalence check, named BinUSE, using under-constrained symbolic execution (USE). USE, a variant of symbolic execution, improves scalability by initiating symbolic execution directly from function entry points and relaxing constraints on function parameters. It eliminates the overhead incurred by path explosion and costly constraints. BinUSE is specifically designed to deliver an assembly function-level equivalence check, enhancing DNN-based binary code search by reducing its false alarms with low cost. Our evaluation shows that BinUSE can enable a general and effective enhancement of four state-of-the-art DNN-based binary code search tools when confronted with challenges posed by different compilers, optimizations, obfuscations, and architectures.
Keyword:
Reverse engineering
symbolic execution
software similarity
deep learning

期刊

IEEE Transactions on Software Engineering 封面图
IEEE Transactions on Software Engineering
IF:
5.6
论文数:
2.8K
被引数:
1.1W

机构

暂无机构信息
引用论文

引用论文

The data availability landscape in seven sub-Saharan African countries and its role in strengthening sugar-sweetened beverage taxation
err2021-04-20
err0
errOAAI
errAgnes Erzse; Safura Abdool Karim; Anne Marie Thow; Gemma Ahaibwe; Hans Justus Amukugo; Gershim Asiki; Lebogang Gaogane; Mulenga M. Mukanu; Twalib Ngoma; Charles Mulindabigwi Ruhara; Milkah N Wanjohi; Karen Hofman
err分享
err收藏
Program Characterization Using Runtime Values and Its Application to Software Plagiarism Detection
err2015-09-01
err35
PREAI
errJhi, Yoon-Chan; Jia, Xiaoqi; Wang, Xinran; Zhu, Sencun; Liu, Peng; Wu, Dinghao
err分享
err收藏
New α-pyrone and phthalide from the Xylariaceae fungus
err2015-06-30
err0
PREAI
errJian Zou; Jun Li; Zu-Yan Wu; Qin Zhao; Gao-Qian Wang; Huan Zhao; Guo-Dong Chen; Xiang Sun; Liang-Dong Guo; Hao Gao
err分享
err收藏
An autonomous in situ detection system for radioactivity measurements in the marine environment
err2008-10-01
err0
PREAI
errC. Tsabaris; C. Bagatelas; Th. Dakladas; C.T. Papadopoulos; R. Vlastou; G.T. Chronis
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
学者 查看更多内容