Testing intermediate representations for binary analysis
Abstract
Binary lifting, which is to translate a binary executable to a high-level intermediate representation, is a primary step in binary analysis. Despite its importance, there are only few existing approaches to testing the correctness of binary lifters. Furthermore, the existing approaches suffer from low test coverage, because they largely depend on random test case generation. In this paper, we present the design and implementation of the first systematic approach to testing binary lifters. We have evaluated the proposed system on 3 state-of-the-art binary lifters, and found 24 previously unknown semantic bugs. Our result demonstrates that writing a precise binary lifter is extremely difficult even for those heavily tested projects.
BibTeX
@inproceedings{Kim-al:ASE17,
author = {Soomin Kim and
Markus Faerevaag and
Minkyu Jung and
Seungil Jung and
DongYeop Oh and
JongHyup Lee and
Sang Kil Cha},
title = {Testing intermediate representations for binary analysis},
booktitle = {ASE},
pages = {353--364},
publisher = {{IEEE} Computer Society},
year = {2017},
}