Return
Using Reduced Execution Flow Graph to Identify Library Functions in Binary Code
DOI:10.1109/TSE.2015.2470241.png)
Abstract
En 中文
Discontinuity and polymorphism of a library function create two challenges for library function identification, which is a key technique in reverse engineering. A new hybrid representation of dependence graph and control flow graph called Execution Flow Graph (EFG) is introduced to describe the semantics of binary code. Library function identification turns to be a subgraph isomorphism testing problem since the EFG of a library function instance is isomorphic to the sub-EFG of this library function. Subgraph isomorphism detection is time-consuming. Thus, we introduce a new representation called Reduced Execution Flow Graph (REFG) based on EFG to speed up the isomorphism testing. We have proved that EFGs are subgraph isomorphic as long as their corresponding REFGs are subgraph isomorphic. The high efficiency of the REFG approach in subgraph isomorphism detection comes from fewer nodes and edges in REFGs and new lossless filters for excluding the unmatched subgraphs before detection. Experimental results show that precisions of both the EFG and REFG approaches are higher than the state-of-the-art tool and the REFG approach sharply decreases the processing time of the EFG approach with consistent precision and recall.
Keywords:
Reverse engineering
static analysis
inline function
library function identification
subgraph isomorphism and graph mining
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
5.6
Papers:
2.9K
Citations:
1.1W
Organization
Cited Papers
Late Bronze Age climate change and the destruction of the Mycenaean Palace of Nestor at Pylos
PLOS ONE
IF0
Restriction Enzyme Body Doubles and PCR Cloning: On the General Use of Type IIS Restriction Enzymes for Cloning
PLoS ONE
IF0

