Decomperson: How Humans Decompile and What We Can Learn From It

Decomperson: How Humans Decompile and What We Can Learn From It
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna
Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna
中科院分区:
其他
文献类型:
--
作者:
Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna

文献摘要

相似文献

人类分析师必须对二进制程序进行逆向工程,这是许多安全任务的先决条件,例如漏洞分析,恶意软件检测和固件重新托管。现有的研究人类逆转器和他们遵循的过程是有限的规模,往往使用定性指标,需要主观评价。在本文中,我们将逆向工程二进制文件的问题重新定义为完美反编译的问题,完美反编译是从二进制程序中恢复源代码的过程,源代码在编译时会产生与原始二进制文件相同的二进制代码。我们开发了一个名为D ECOMPERSON的工具,在一次大型安全竞赛中为一组逆向工程师提供支持,该竞赛旨在收集参与者的逆向工程过程的信息,其明确的目标是实现完美的反编译。超过150人参与,我们收集了超过35,000个代码提交,这是迄今为止最大的手动逆向工程数据集。这包括超过300次成功的完美反编译尝试的快照。在本文中,我们将展示如何完美的反编译允许编程分析这样的大型数据集,提供了新的见解逆向工程过程。
Human analysts must reverse engineer binary programs as a prerequisite for a number of security tasks, such as vulnerability analysis, malware detection, and firmware re-hosting. Existing studies of human reversers and the processes they follow are limited in size and often use qualitative metrics that require subjective evaluation. In this paper, we reframe the problem of reverse engineering binaries as the problem of perfect decompilation , which is the process of recovering, from a binary program, source code that, when compiled, produces binary code that is identical to the original binary. This gives us a quantitative measure of understanding, and lets us examine the reversing process programmatically.Wedevelopedatool, called D ECOMPERSON , that supported a group of reverse engineers during a large-scale security competition designed to collect information about the participants’ reverse engineering process, with the well-defined goal of achieving perfect decompilation. Over 150 people par-ticipated,andwe collectedmore than 35,000 code submissions, the largest manual reverse engineering dataset to date. This includes snapshots of over 300 successful perfect decompilation attempts. In this paper, we show how perfect decompilation allows programmatic analysis of such large datasets, providing new insights into the reverse engineering process.