Static Analysis of Binary Executables

Static Analysis of Binary Executables
复制标题

二进制可执行文件的静态分析

DOI:
--
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
Steve Hanov
Steve Hanov
中科院分区:
--
文献类型:
--
作者:
Steve Hanov

文献摘要

被引文献

相似文献

本文是对二进制可执行程序的静态程序分析技术使用的调查。静态分析技术通常用于程序的源代码,通常是高级语言。可以将它们直接应用于已编译程序的机器码。挑战之一是建立过程的控制流图,因为间接分支指令接受目标地址寄存器的内容。程序切片技术可以用来将汇编代码减少到最小可能的程序,以计算该寄存器的值,并确定寄存器中的值的范围。另一个问题是拆卸本身。在具有不同大小的指令的体系结构上,很难在由代码和数据组成的部分中定位第一个机器代码指令的开始。此外,恶意代码可以利用反汇编的困难来隐藏其存在。为了建立控制流图和调用图,已经开发了各种静态分析技术来分析这样的程序。最后,类型状态技术已经被开发出来,以验证机器代码是否符合其接口,并且不会改变它不应该改变的内存区域。
This paper is a survey of the use of static program analysis techniques on binary executables. Static analysis techniques are often used on a program’s source code, which is usually a high level language. It is possible to apply them directly on the machine code of a compiled program. One of the challenges is building up a control flow graph of a procedure, since indirect branch instructions accept the contents of a register for the destination address. Program slicing techniques can be used to reduce the assembly code to the smallest possible program to compute the value of that register, and determine the range of values in the register. Another problem is disassembly itself. On architectures with instructions of varying size, it is difficult to locate the start of the first machine code instruction in a section consisting of both code and data. Also, malicious code could take advantage of the difficulties in disassembly to hide its existence. Various static analysis techniques have been developed to analyze such programs, in order to build up a control flow graph and a call graph. Finally, type-state techniques have been developed to verify that machine code conforms to its interface, and does not alter areas of memory which it should not.