Program Obfuscation via ABI Debiasing

Program Obfuscation via ABI Debiasing
复制标题

DOI:
10.1145/3485832.3488017
复制
发表时间:
2021-12
期刊:
Proceedings of the 37th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
David Demicco;R. Erinfolami;Aravind Prakash
David Demicco;R. Erinfolami;Aravind Prakash
中科院分区:
其他
文献类型:
--
作者:
David Demicco;R. Erinfolami;Aravind Prakash

文献摘要

相似文献

Itanium ABI是最流行的C++ ABI,它定义了在C++中实现底层面向对象概念所必需的数据结构。具体来说,名称修改规则、对象和VTable布局、对齐等都是ABI强制要求的。坚持ABI会带来不良的副作用。虽然它允许互操作性,但过去的研究工作表明,它提供了强大的推理点,攻击者可以利用这些推理点通过二进制逆向工程来揭示敏感的设计信息。在这项工作中,我们的目标是减少攻击者成功地逆向工程二进制的能力。我们通过消除我们所说的ABI偏差来做到这一点,即,由于编译器遵守ABI而表现出的反向工程偏见。具体来说,我们确定了两种类型的ABI偏见,过去的C++二进制文件的逆向工程工作的核心:VTable排序偏差和函数指针偏差。我们提出了基于编译器的技术,可以正确和有效地debias从上述偏见给定的二进制文件。我们评估我们的概念验证的实现语料库的真实的世界的程序的二进制大小,正确性和性能。与基线相比,我们报告了二进制大小平均增加1.42%,非常低的性能开销,最后,与基线相比,正确执行评估程序。最后,我们通过阻碍DeClassifier(一个最先进的C++逆向工程框架)来证明我们的方法的有效性。
The Itanium ABI is the most popular C++ ABI that defines data structures essential to implement underlying object-oriented concepts in C++. Specifically, name mangling rules, object and VTable layouts, alignment, etc. are all mandated by the ABI. Adherence to the ABI comes with undesirable side effects. While it allows interoperability, past research efforts have shown that it provides robust inference points that an attacker can leverage to reveal sensitive design information through binary reverse engineering. In this work, we aim to reduce the ability of an attacker to successfully reverse engineer a binary. We do this via removal of what we call ABI Bias, i.e., the reverse engineering bias that manifests due to a compiler’s adherence to the ABI. Specifically, we identify two types of ABI biases that are central to past reverse engineering works on C++ binaries: VTable ordering bias and Function Pointer bias. We present compiler-based techniques that can correctly and efficiently debias a given binary from the aforementioned biases. We evaluate our proof-of-concept implementation on a corpus of real world programs for binary size, correctness and performance. We report an average increase of 1.42% in binary size compared to the baseline, very low performance overhead and lastly, correct execution of evaluation programs in comparison to the baseline. Finally, we demonstrate efficacy of our approach by hindering DeClassifier, a state-of-the-art C++ reverse engineering framework.