Binary code analysis plays a central role in numerous applications in software security, performance optimization, reverse engineering, and so on. Existing techniques need to first disassemble binaries into functions in assembly code before an analysis can be performed. However, disassembly and function identification have proven to be major challenges for complex variable-length instruction sets such as the x86. A recent trend has been to use static analysis to improve the accuracy of these tasks. This raises a chicken-and-egg problem: a disassembly is needed for static analysis, but a static analysis is needed for accurate disassembly! We overcome this problem by developing a novel static analysis approach that can operate before committing to a disassembly. Our analysis operates on the output of exhaustive disassembly that considers each possible offset in a binary as an instruction, and constructs what is known as a super-set control-flow graph (CFG). The central technical challenge in analyzing this CFG is that it mixes legitimate instructions with unintended ones, causing analysis results from invalid code paths to pollute legitimate ones. To overcome this challenge, we begin with a key new insight that if we focus on backward analyses, we can ensure accuracy of analysis results at intended instructions even though we have no idea where these intended instructions are! Moreover, our analysis operates in time that is linear in the size of the binary. Specifically, in O(n) total time, it yields analysis results for every one of the n offsets in an n-byte binary. For this task, it is orders of magnitude faster than previous techniques, as the previous techniques typically need to repeat the analysis many times.
Wed 17 JunDisplayed time zone: Mountain Time (US & Canada) change
14:00 - 15:40 | Static Analysis 1PLDI Research Papers at Flatirons 4 Chair(s): Milijana Surbatovich University of Maryland at College Park | ||
14:00 20mTalk | Flow-Analysis-Based Closure Optimization PLDI Research Papers John Reppy University of Chicago, Olin Shivers Northeastern University, Byron Zhong University of Chicago DOI Pre-print | ||
14:20 20mTalk | SSA without Dominance for Higher-Order Programs PLDI Research Papers DOI Pre-print | ||
14:40 20mTalk | Analyzing Bytes: Pre-Disassembly Static Binary Analysis PLDI Research Papers Huan Nguyen Google, Soumyakant Priyadarshan Stony Brook University, Chencheng Jiang Stony Brook University, R. Sekar Stony Brook University DOI | ||
15:00 20mTalk | Exploiting Sophisticated Static Analysis for Verilog PLDI Research Papers Qinlin Chen Nanjing University, Nairen Zhang Nanjing University, Jinpeng Wang Nanjing University, Jiacai Cui Nanjing University, Tian Tan Nanjing University, Xiaoxing Ma Nanjing University, Chang Xu Nanjing University, Jian Lu Nanjing University, Yue Li Nanjing University DOI | ||