
Für unser CCS24-Papier 🏆 „ReSym: Harnessing LLMs to Recover Variable and Data Structure Symbols from Stripped Binaries" von Danning Xie, Zhuo Zhang, Nan Jiang, Xiangzhe Xu, Lin Tan und Xiangyu Zhang. 🏆 Gewinner des ACM SIGSAC Distinguished Paper Award
Dieses Repository stellt Artefakte für das Paper "ReSym: Harnessing LLMs to Recover Variable and Data Structure Symbols from Stripped Binaries" (CCS 2024) bereit.
🏆 Gewinner des ACM SIGSAC Distinguished Paper Award
Hinweis: Wir pflegen und aktualisieren unsere Artefakte aktiv. Bitte stellen Sie sicher, dass Sie die neueste Version verwenden.
process_data. Es erzeugt Trainingsdaten mit Ground-Truth-Symbolinformationen. Das Skript lässt sich per Knopfdruck ausführen, und Nutzungshinweise sind im Ordner enthalten.ReSym_rawdata). Dies umfasst die rohen Binärdateien und den zugehörigen dekompilierten Code, die wir in diesem Projekt verwendet haben:
bin/: Enthält rohe nicht gestrippte Binärdateien mit Debug-Informationen.decompiled/: Dekompilierter Code aus vollständig gestrippten Binärdateien.metadata.json: Metadaten für die Binärdateien, einschließlich Projektinformationen.training_src für die Modelle VarDecoder und FieldDecoder.ReSym_data). Dies umfasst: Trainingsdaten, Testdaten und Vorhersageergebnisse für FieldDecoder und VarDecoder.posterior_reasoning. Details und Anweisungen finden Sie in diesem Ordner.training_src.@inproceedings{10.1145/3658644.3670340,
author = {Xie, Danning and Zhang, Zhuo and Jiang, Nan and Xu, Xiangzhe and Tan, Lin and Zhang, Xiangyu},
title = {ReSym: Harnessing LLMs to Recover Variable and Data Structure Symbols from Stripped Binaries},
year = {2024},
isbn = {9798400706363},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
url = {https://doi.org/10.1145/3658644.3670340},
doi = {10.1145/3658644.3670340},
abstract = {Decompilation aims to recover a binary executable to the source code form and hence has a wide range of applications in cyber security, such as malware analysis and legacy code hardening. A prominent challenge is to recover variable symbols, including both primitive and complex types such as user-defined data structures, along with their symbol information such as names and types. Existing efforts focus on solving parts of the problem, e.g., recovering only types (without names) or only local variables (without user-defined structures). In this paper, we propose ReSym, a novel hybrid technique that combines Large Language Models (LLMs) and program analysis to recover both names and types for local variables and user-defined data structures. Our method encompasses fine-tuning two LLMs to handle local variables and structures, respectively. To overcome the token limitations inherent in current LLMs, we devise a novel Prolog-based algorithm to aggregate and cross-check results from multiple LLM queries, suppressing uncertainty and hallucinations. Our experiments show that ReSym is effective in recovering variable information and user-defined data structures, substantially outperforming the state-of-the-art methods.},
booktitle = {Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security},
pages = {4554–4568},
numpages = {15},
keywords = {large language models, program analysis, reverse engineering},
location = {Salt Lake City, UT, USA},
series = {CCS '24}
}