arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.13042cs.CRcs.PL

InSPECtor:通过代理提升SLEIGH处理器规范的准确性

InSPECtor: Improving SLEIGH Processor Specification Veracity via Proxy

Michael Chesser, Paul Quirk, Douglas Cooke, Guy Farrelly, Surya Nepal, Damith C. Ranasinghe

首次发表
浏览论文内容

中文总结 AI 辅助

本研究开发了InSPECtor测试框架,通过代理差异测试验证开源SLEIGH处理器规范,发现38920处差异及125个错误,提出8项建议以提升规范保真度,增强下游工具可靠性。

中文摘要 AI 辅助

处理器规范是反汇编器、反编译器和模拟器等关键安全及程序分析工具的基础,但其正确性很少被检查。规范中的错误会扭曲程序行为、隐藏漏洞,并催生规避分析的技术。验证处理器规范并非易事。本研究首次系统性验证主要用于Ghidra的开源SLEIGH语言规范,是一项重要工作。我们设计并实现了基于代理自动预言机验证策略的测试框架,该方法利用规范自身编码的结构枚举可解码的指令形式,生成针对性初始状态,随后通过对比执行处理器规范的模拟器与硬件参考,对这些指令的成功解码和仿真进行差异测试。将InSPECtor应用于x86-64、AArch64、ARM/Thumb、RISC-V、MSP430等不同开源规范(涵盖规范风格、作者偏好及指令集架构设计的差异),我们发现了超过38920处差异,这些差异导致125个独特的错误并提出修复方案,识别出解码缺陷、语义缺陷及跨厂商不一致问题。我们提炼出8项具体建议以推动未来改进。本研究强调了规范正确性的重要性,提供了实用工具以大幅提升SLEIGH处理器规范的保真度,增强下游安全与分析工具的可靠性。

英文摘要

Processor specifications underpin critical security and program- analysis tools such as disassemblers, decompilers, and emulators, yet, their correctness is rarely examined. Errors in specifications distort program behaviour, obscure vulnerabilities, and enable analysis-evasion techniques. Validating processor specifications is a non-trivial task. Our study is a significant undertaking to enable, for the first time, the systematic validation of open-source SLEIGH language specifications, predominantly used by Ghidra. We design and implement a testing framework based on an automated oracle validation strategy by proxy. Our approach leverages the structure encoded in a specification itself to enumerate decodable instruction forms and generate targeted initial states. Then differentially test the successful decoding and emulation of those instructions by comparing emulators exercising the processor specification against hardware references. Applying InSPECtor across diverse, open-source specifications---x86-64, AArch64, ARM/Thumb, RISC-V, MSP430---embedding differences in specification styles, author preferences, and instruction set architecture designs, we uncovered over 38,920 discrepancies that led to 125 unique bugs with proposed fixes, identifying decoding and semantic defects as well as cross-vendor inconsistencies. We distill our findings into 8 concrete recommendations to drive future improvements. Our work underscores the importance of specification correctness and provides a practical tool to substantially improve the fidelity of SLEIGH processor specifications, strengthening the reliability of downstream security and analysis tools.

补充信息

↑