kirancodes.me
To Proof Maintenance & Beyond!

FunProbe: Probing Functions from Binary Code through Probabilistic Analysis

Soomin Kim, Hyungseok Kim, Sang Kil Cha

Abstract

Current function identification techniques have been mostly focused on a specific set of binaries compiled for a specific CPU architecture. While recent deep-learning-based approaches theoretically can handle binaries from different architectures, they require significant computation resources for training and inference, making their use less practical. Furthermore, due to the lack of interpretability of such models, it is fundamentally difficult to gain insight from them. Hence, in this paper, we propose FunProbe, an efficient system for identifying functions from binaries using probabilistic inference. In particular, we identify 16 architecture-neutral hints for function identification, and devise an effective method to combine them in a probabilistic framework. We evaluate our tool on a large dataset consisting of 19,872 real-world binaries compiled for six major CPU architectures. The results are promising. FunProbe shows the best accuracy compared to five state-of-the-art tools we tested, while it takes only 6 seconds on average to analyze a single binary. Notably, FunProbe is 6× faster on average in identifying functions than XDA, a state-of-the-art deep-learning tool that leverages GPU in its inference phase.

BibTeX
@inproceedings{Kim-al:FSE23,
  author    = {Soomin Kim and
               Hyungseok Kim and
               Sang Kil Cha},
  title     = {{FunProbe:} Probing Functions from Binary Code through Probabilistic Analysis},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {1419--1430},
  publisher = {{ACM}},
  year      = {2023},
}

Related papers