MBA-Blast: Unveiling and Simplifying Mixed Boolean-Arithmetic Obfuscation

MBA-Blast: Unveiling and Simplifying Mixed Boolean-Arithmetic Obfuscation
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Binbin Liu;Junfu Shen;Jiang Ming;Qilong Zheng;Jing Li;Dongpeng Xu
Binbin Liu;Junfu Shen;Jiang Ming;Qilong Zheng;Jing Li;Dongpeng Xu
中科院分区:
其他
文献类型:
--
作者:
Binbin Liu;Junfu Shen;Jiang Ming;Qilong Zheng;Jing Li;Dongpeng Xu

文献摘要

被引文献

相似文献

混合布尔算术(MBA)混淆是一种从简单的表达式到难以理解和分析的表示的保持语义的转换。更具体地说,该混淆技术包括算术运算(例如,加法和整数运算)和布尔运算(例如,fi、OR和NOT)的混合使用。带有MBA混淆的二进制代码可以有效地隐藏秘密数据/算法,使其不受静态和动态逆向工程的影响,包括利用SMT解算器进行的高级分析。遗憾的是,针对MBA的去模糊研究仍处于初级阶段:最先进的解决方案,如模式匹配、位爆破和程序综合,要么遭受严重的性能损失,要么是为特定的fic MBA模式设计的,或者在实践中产生太多虚假的Simplifi运算结果。在这篇文章中,我们首先fi揭开了mba混淆的潜在机制。我们的深入研究揭示了MBA在1位和n位变量之间转换的隐藏的双向特征。我们利用了这一特性,并提出了一个可行的解决方案来有效地利用fi混淆来对代码进行混淆。我们的主要见解是,MBA转换在1位和n位变量上的行为方式是相同的。我们提供了一个数学证明来保证这个fi定义的正确性。我们进一步开发了一种新的技术,通过在1位空间中进行算术简化,将MBA表达式简化为标准的简单形式。我们已经将这个想法作为一个开源原型实现,名为MBA-BLAST,并在一个拥有大约10,000个MBA表达的全面数据集上对其进行了评估。我们还在真实世界的二进制代码去模糊场景中测试了我们的方法,这表明MBA-BLAST可以帮助人类分析师利用SMT解算器的全部力量。与已有的工作相比,fi-BLAST是最通用、最有效的MBA去模糊技术;它有坚实的理论基础,而且成功率最高,开销可以忽略不计。
Mixed Boolean-Arithmetic (MBA) obfuscation is a method to perform a semantics-preserving transformation from a simple expression to a representation that is hard to understand and analyze. More specifically, this obfuscation technique consists of the mixture usage of arithmetic operations (e.g., ADD and IMUL) and Boolean operations (e.g., AND, OR, and NOT). Binary code with MBA obfuscation can effectively hide the secret data/algorithm from both static and dynamic reverse engineering, including advanced analyses utilizing SMT solvers. Unfortunately, deobfuscation research against MBA is still in its infancy: state-of-the-art solutions such as pattern matching, bit-blasting, and program synthesis either suffer from severe performance penalties, are designed for specific MBA patterns, or generate too many false simplifica-tion results in practice. In this paper, we first demystify the underlying mechanism of MBA obfuscation. Our in-depth study reveals a hidden two-way feature regarding MBA transformation between 1-bit and n-bit variables. We exploit this feature and propose a viable solution to efficiently deobfuscate code with MBA obfuscation. Our key insight is that MBA transformations behave in the same way on 1-bit and n-bit variables. We provide a mathematical proof to guarantee the correctness of this finding. We further develop a novel technique to simplify MBA expressions to a normal simple form by arithmetic reduction in 1-bit space. We have implemented this idea as an open-source prototype, named MBA-Blast , and evaluated it on a comprehensive dataset with about 10 , 000 MBA expressions. We also tested our method in real-world, binary code deobfuscation scenarios, which demonstrate that MBA-Blast can assist human analysts to harness the full strength of SMT solvers. Compared with existing work, MBA-Blast is the most generic and efficient MBA deobfuscation technique; it has a solid theoretical underpinning, as well as, the highest success rate with negligible overhead.