不留任何位:使用暴力提升实现完全静态的二进制重编译
No Bit Left Behind: Using Brute-Force Lifting to Achieve Fully Static Binary Recompilation
浏览论文内容
中文总结 AI 辅助
本文提出一种完全静态的二进制重编译系统,通过暴力提升整个二进制文件构建超集CFG,无需运行时支持,实现从x86-64到LLVM IR及AArch64的可靠翻译。
中文摘要 AI 辅助
二进制重编译是一种直接对可执行代码进行操作的技术。它有望自动化两项重要任务:为遗留二进制文件改造安全缓解措施,以及跨指令集架构(ISA)迁移二进制文件。然而,目前还没有完全自动化的系统能够可靠地将任意二进制可执行文件提升到编译器中间表示(IR)(如LLVM IR),也没有系统能够完全静态且可靠地将非平凡的二进制可执行文件从一种ISA翻译到另一种ISA。主要的根本问题在于,静态恢复程序的控制流图(CFG)在一般情况下是不可能的:计算分支可以跳转到无法在不实际运行程序的情况下确定的目标。现有系统诉诸于运行时回退机制,要求将大部分二进制翻译机制随翻译后的程序一起部署在目标机器上。本文提出了一种完全静态的、全程序的二进制提升系统,在目标上不需要任何运行时翻译支持。我们不试图区分代码和数据,而是将每个字节偏移视为潜在的分支目标,并以暴力方式提升整个二进制文件,构建一个保守地包含所有可行控制流的超集CFG。静态无法解析的计算分支因此被简化为对调度表的查找,该调度表指向相应的翻译后控制流路径。我们已将该方法实现为一个从x86-64二进制文件到LLVM IR的原型二进制重编译器,不需要任何代码/数据启发式方法。我们通过完全静态的交叉编译到AArch64来验证它,这是通过重用现有的LLVM后端而无需修改实现的。
英文摘要
Binary recompilation is a technique for operating directly on executable code. It promises to automate two important tasks: retrofitting security mitigations onto legacy binaries, and migrating binaries across instruction set architectures (ISAs). Yet today, there is no fully automated system that can reliably lift arbitrary binary executables to a compiler intermediate representation (IR) such as LLVM IR, or that can fully statically and reliably translate non-trivial binary executables from one ISA to another. The main underlying problem is that recovering a program's control flow graph (CFG) statically is impossible in general: computed branches can jump to targets that cannot be determined without actually running the program. Existing systems resort to runtime fallback mechanisms, requiring a significant portion of the binary translation machinery to accompany the translated program on the target machine. This article presents a fully static, whole-program binary lifting system requiring no runtime translation support on the target. Rather than attempting to distinguish code from data, we treat every byte offset as a potential branch target and lift the entire binary in a brute-force manner, constructing a superset CFG that conservatively contains all feasible control flows. Statically unresolvable computed branches are thereby reduced to lookups in a dispatch table that points to the corresponding translated control flow path. We have implemented this approach as a prototype binary recompiler from x86-64 binaries to LLVM IR, requiring no code/data heuristics. We validate it with a fully static cross-compilation to AArch64, achieved by reusing existing LLVM backends with no modification.
发表机构
- University of California, Irvine(加州大学尔湾分校)
机构由 AI 辅助整理,请以论文原文为准。