Cornucopia : A Framework for Feedback Guided Generation of Binaries

Cornucopia : A Framework for Feedback Guided Generation of Binaries
复制标题

DOI:
10.1145/3551349.3561152
复制
发表时间:
2022-09
期刊:
Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering
影响因子:
--
通讯作者:
Vidushi Singhal;A. Pillai;Charitha Saumya;Milind Kulkarni;Aravind Machiry
Vidushi Singhal;A. Pillai;Charitha Saumya;Milind Kulkarni;Aravind Machiry
中科院分区:
其他
文献类型:
--
作者:
Vidushi Singhal;A. Pillai;Charitha Saumya;Milind Kulkarni;Aravind Machiry

文献摘要

相似文献

二进制分析是许多安全性和软件工程应用程序所需的功能论文,我们提出了一个架构,这是一个不可知的自动化框架,可以通过利用编译器的优化和反馈指导的学习来产生相应的程序来源的大量二进制文件。 ,ARM,MIPS)每个程序的平均二进制文件均优于Bintuner [53],我们的实验揭示了LLVM优化调度程序的问题。 ANGR,Ghidra,Ida和Radare使用聚宝盆生成的二进制文件,揭示了这些工具的各种问题,我们在ANGR中发现了263次崩溃,并在IDA中揭示了我们的差异测试。这些工具还测试了ASM2VEC,安全和Debin的机器学习工具,声称捕获二进制语义,并表明它们的表现不佳(例如,Debin F1得分从报告的63.1%降至12.9%) ,我们详尽的评估表明,聚宝盆是生成有效测试二进制分析技术的有效机制。
Binary analysis is an important capability required for many security and software engineering applications. Consequently, there are many binary analysis techniques and tools with varied capabilities. However, testing these tools requires a large, varied binary dataset with corresponding source-level information. In this paper, we present Cornucopia, an architecture agnostic automated framework that can generate a plethora of binaries from corresponding program source by exploiting compiler optimizations and feedback-guided learning. Our evaluation shows that Cornucopia was able to generate 309K binaries across four architectures (x86, x64, ARM, MIPS) with an average of 403 binaries for each program and outperforms BinTuner [53], a similar technique. Our experiments revealed issues with the LLVM optimization scheduler resulting in compiler crashes (∼ 300). Our evaluation of four popular binary analysis tools angr, Ghidra, ida, and radare, using Cornucopia generated binaries, revealed various issues with these tools. Specifically, we found 263 crashes in angr and one memory corruption issue in ida. Our differential testing on the analysis results revealed various semantic bugs in these tools. We also tested machine learning tools, Asm2Vec, SAFE, and Debin, that claim to capture binary semantics and show that they perform poorly (e.g., Debin F1 score dropped to 12.9% from reported 63.1%) on Cornucopia generated binaries. In summary, our exhaustive evaluation shows that Cornucopia is an effective mechanism to generate binaries for testing binary analysis techniques effectively.