Verifiably Correct Lifting of Position-Independent x86-64 Binaries to Symbolized Assembly | Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security

· ACM Conferences

7 min read Original article ↗

Abstract

Abstract

We present an approach to lift position-independent x86-64 binaries to symbolized NASM. Symbolization is a decompilation step that enables binary patching: functions can be modified, and instructions can be interspersed. Moreover, it is the first abstraction step in a larger decompilation chain. The produced NASM is recompilable, and we extensively test the recompiled binaries to see if they exhibit the same behavior as the original ones. In addition to testing, the produced NASM is accompanied with a certificate, constructed in such a way that if all theorems in the certificate hold, symbolization has occurred correctly. The original and recompiled binary are lifted again with a third-party decompiler (Ghidra). These representations, as well as the certificate, are loaded into the Isabelle/HOL theorem prover, where proof scripts ensure that correctness can be proven automatically. We have applied symbolization to various stripped binaries from various sources, from various compilers, and ranging over various optimization levels. We show how symbolization enables binary-level patching, by tackling challenges originating from industry.

AI Summary

AI-Generated Summary (Experimental)

This summary was generated using automated tools and was not authored or reviewed by the article's author(s). It is provided to support discovery, help readers assess relevance, and assist readers from adjacent research areas in understanding the work. It is intended to complement the author-supplied abstract, which remains the primary summary of the paper. The full article remains the authoritative version of record. Click here to learn more.

Click here to comment on the accuracy, clarity, and usefulness of this summary. Doing so will help inform refinements and future regenerated versions.

To view this AI-generated plain language summary, you must have Premium access.

Formats available

You can view the full content in the following formats:

References

[1]

Christel Baier and Joost-Pieter Katoen. Principles of model checking. MIT press, 2008.

[2]

Gogul Balakrishnan, Radu Gruian, Thomas Reps, and Tim Teitelbaum. Codesurfer/x86'a platform for analyzing x86 executables. In Rastislav Bodik, editor, Compiler Construction, pages 250--254, Berlin, Heidelberg, 2005. Springer Berlin Heidelberg.

[3]

Christian Bienia, Sanjeev Kumar, Jaswinder Pal Singh, and Kai Li. The parsec benchmark suite: Characterization and architectural implications. In Proceedings of the 17th international conference on Parallel architectures and compilation techniques, pages 72--81, 2008.

[4]

Tyler Bletsch, Xuxian Jiang, Vince W Freeh, and Zhenkai Liang. Jump-oriented programming: a new class of code-reuse attack. In Proceedings of the 6th ACM symposium on information, computer and communications security, pages 30--40, 2011.

[5]

David Brumley, JongHyup Lee, Edward J. Schwartz, and Maverick Woo. Native x86 decompilation using semantics-preserving structural analysis and iterative control-flow structuring. In Samuel T. King, editor, Proceedings of the 22th USENIX Security Symposium, Washington, DC, USA, August 14--16, 2013, pages 353--368. USENIX Association, 2013.

[6]

Nicholas Carlini and David Wagner. ROP is still dangerous: Breaking modern defenses. In 23rd USENIX Security Symposium (USENIX Security 14), pages 385--399, 2014.

[7]

Cristina Cifuentes and K John Gough. Decompilation of binary programs. Software: Practice and Experience, 25(7):811--829, 1995.

[8]

Sivarama P Dandamudi. Installing and using NASM. Guide to Assembly Language Programming in Linux, pages 153--166, 2005.

[9]

Lesly-Ann Daniel, Sébastien Bardin, and Tamara Rezk. Binsec/rel: Efficient relational symbolic execution for constant-time at binary-level. In 2020 IEEE Symposium on Security and Privacy (SP), pages 1021--1038. IEEE, 2020.

[10]

Jeremy Dawson. Isabelle theories for machine words. Electronic Notes in Theoretical Computer Science, 250(1):55--70, 2009.

[11]

Artem Dinaburg and Andrew Ruef. McSema: Static translation of x86 instructions to LLVM. In ReCon 2014 Conference, Montreal, Canada, 2014.

[12]

Gregory J Duck, Xiang Gao, and Abhik Roychoudhury. Binary rewriting without control flow recovery. In Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation, pages 151--163, 2020.

[13]

Alexander Fokin, Egor Derevenetc, Alexander Chernov, and Katerina Troshina. SmartDec: Approaching C decompilation. In 2011 18th Working Conference on Reverse Engineering, pages 347--356, October 2011.

[14]

Shilpi Goel. Formal Verification of Application and System Programs Based on a Validated x86 ISA Model. PhD thesis, The University of Texas at Austin, 2016.

[15]

R. Nigel Horspool and Nenad Marovac. An approach to the problem of detranslation of computer programs. The Computer Journal, 23(3):223--229, 1980.

[16]

Yongzhe Huang, Vikram Narayanan, David Detweiler, Kaiming Huang, Gang Tan, Trent Jaeger, and Anton Burtsev. KSplit: Automating device driver isolation. In 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22), pages 613--631, Carlsbad, CA, July 2022. USENIX Association.

[17]

Florian Kammüller, Markus Wenzel, and Lawrence C Paulson. Locales a sectioning concept for isabelle. In Theorem Proving in Higher Order Logics: 12th International Conference, TPHOLs' 99 Nice, France, September 14--17, 1999 Proceedings 12, pages 149--165. Springer, 1999.

[18]

Stephen Kell, Dominic P. Mulligan, and Peter Sewell. The missing link: explaining elf static linking, semantically. ACM SIGPLAN Notices, 51(10):607--623, oct 2016.

[19]

Sun Hyoung Kim, Dongrui Zeng, Cong Sun, and Gang Tan. BinPointer: towards precise, sound, and scalable binary-level pointer analysis. In Proceedings of the 31st ACM SIGPLAN International Conference on Compiler Construction, pages 169--180, 2022.

[20]

Jakub Kroustek, Peter Matula, and P Zemek. RetDec: An open-source machine-code decompiler. In July 2018, 2017.

[21]

Xavier Leroy. Formal verification of a realistic compiler. Communications of the ACM, 52(7):107--115, 2009.

[22]

Daniel Matichuk, Toby Murray, and Makarius Wenzel. Eisbach: A proof method language for isabelle. Journal of Automated Reasoning, 56:261--282, 2016.

[23]

Michael Matz, Jan Hubicka, Andreas Jaeger, and Mark Mitchell. System V Application Binary Interface AMD64 Architecture Processor Supplement, 2012.

[24]

Alan Mycroft. Type-based decompilation (or program reconstruction via type reconstruction). In European Symposium on Programming, pages 208--223. Springer, 1999.

[25]

Magnus O. Myreen, Michael J. C. Gordon, and Konrad Slind. Decompilation into logic -- improved. In 2012 Formal Methods in Computer-Aided Design (FMCAD), pages 78--81. IEEE, 2012.

[26]

Shravan Narayan, Craig Disselkoen, Tal Garfinkel, Nathan Froyd, Eric Rahm, Sorin Lerner, Hovav Shacham, and Deian Stefan. Retrofitting fine grain isolation in the firefox renderer. In 29th USENIX Security Symposium (USENIX Security 20), pages 699--716. USENIX Association, August 2020.

[27]

George C Necula. Translation validation for an optimizing compiler. In Proceedings of the ACM SIGPLAN 2000 conference on Programming language design and implementation, pages 83--94, 2000.

[28]

Tobias Nipkow, Lawrence C. Paulson, and Markus Wenzel. Isabelle/HOL: A Proof Assistant for Higher-Order Logic, volume 2283. Springer Science & Business Media, 2002.

[29]

Amir Pnueli, Michael Siegel, and Eli Singerman. Translation validation. In Tools and Algorithms for the Construction and Analysis of Systems: 4th International Conference, TACAS'98 Held as Part of the Joint European Conferences on Theory and Practice of Software, ETAPS'98 Lisbon, Portugal, March 28--April 4, 1998 Proceedings 4, pages 151--166. Springer, 1998.

[30]

Nilo Redini, Ruoyu Wang, Aravind Machiry, Yan Shoshitaishvili, Giovanni Vigna, and Christopher Kruegel. BinTrimmer: Towards static binary debloating through abstract interpretation. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pages 482--501. Springer, 2019.

[31]

Ryan Roemer, Erik Buchanan, Hovav Shacham, and Stefan Savage. Return-oriented programming: Systems, languages, and applications. ACM Transactions on Information and System Security (TISSEC), 15(1):1--34, 2012.

[32]

Nick Roessler and André DeHon. Scalpel: Exploring the limits of tag-enforced compartmentalization. J. Emerg. Technol. Comput. Syst., 18(1), sep 2021.

[33]

Thomas Arthur Leck Sewell, Magnus O Myreen, and Gerwin Klein. Translation validation for a verified os kernel. In Proceedings of the 34th ACM SIGPLAN conference on Programming language design and implementation, pages 471--482, 2013.

[34]

Vedvyas Shanbhogue, Deepak Gupta, and Ravi Sahita. Security analysis of processor instruction set architecture for enforcing control-flow integrity. In Proceedings of the 8th International Workshop on Hardware and Architectural Support for Security and Privacy, pages 1--11, 2019.

[35]

Freek Verbeek, Joshua Bockenek, Zhoulai Fu, and Binoy Ravindran. Formally verified lifting of c-compiled x86--64 binaries. In Proceedings of the 43rd ACM SIGPLAN International Conference on Programming Language Design and Implementation, pages 934--949, 2022.

[36]

Freek Verbeek, Pierre Olivier, and Binoy Ravindran. Sound C code decompilation for a subset of x86--64 binaries. In Proceedings of the 18th International Conference on Software Engineering and Formal Methods, SEFM 2020, September 2020.

[37]

Ruoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry, John Grosen, Paul Grosen, Christopher Kruegel, and Giovanni Vigna. Ramblr: Making reassembly great again. In Proceedings of the 24th Annual Symposium on Network and Distributed System Security, NDSS'17, 2017.

[38]

Shuai Wang, Pei Wang, and Dinghao Wu. Reassembleable disassembling. In 24th USENIX Security Symposium (USENIX Security 15), pages 627--642, 2015.

[39]

Makarius Wenzel. Parallel proof checking in isabelle/isar. PLMMS, pages 13--29, 2009.

[40]

Jianzhou Zhao, Santosh Nagarakatte, Milo MK Martin, and Steve Zdancewic. Formalizing the LLVM intermediate representation for verified program transformations. In Proceedings of the 39th annual ACM SIGPLAN-SIGACT symposium on Principles of programming languages, pages 427--440, 2012.