StateFormer: fine-grained type recovery from binaries using generative state modeling
Abstract
Binary type inference is a critical reverse engineering task supporting many security applications, including vulnerability analysis, binary hardening, forensics, and decompilation. It is a difficult task because source-level type information is often stripped during compilation, leaving only binaries with untyped memory and register accesses. Existing approaches rely on hand-coded type inference rules defined by domain experts, which are brittle and require nontrivial effort to maintain and update. Even though machine learning approaches have shown promise at automatically learning the inference rules, their accuracy is still low, especially for optimized binaries.
BibTeX
@inproceedings{Pei-al:FSE21,
author = {Kexin Pei and
Jonas Guan and
Matthew Broughton and
Zhongtian Chen and
Songchen Yao and
David Williams{-}King and
Vikas Ummadisetty and
Junfeng Yang and
Baishakhi Ray and
Suman Jana},
title = {{StateFormer:} fine-grained type recovery from binaries using generative state modeling},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {690--702},
publisher = {{ACM}},
year = {2021},
}