Binary program disassembling method and device
By filtering and superset disassembly identifying code portals, and combining pre-trained model screening and identification portal instructions, the problem of difficult to balance the accuracy, recall and speed of the disassembly algorithm in the prior art is solved, and efficient and accurate disassembly effect is achieved.
Patent Information
- Application Number
- CN202510219882.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-06-13
AI Technical Summary
Existing disassembly algorithms have difficulty in achieving the optimal balance between accuracy, recall and speed, resulting in increased cost and complexity when applied to practical problems.
By obtaining the original bytes of the binary program and dividing it into multiple bytecode segments, the target bytecode segments containing the valid code entry are filtered out, superset disassembly generate candidate assembly paths, and combining the pre-trained model to filter the target assembly path and entry instructions, and generate target assembly instructions as the starting point of recursive disassembly.
A disassembly method that takes into account speed, accuracy and recall is realized, which improves the efficiency and accuracy of disassembly and reduces the probability of manual intervention and error.
Smart Images

Figure CN120144136A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a binary program disassembly method and apparatus. Background Art
[0002] Disassembly is the basis for many binary analysis tasks, including reverse engineering, binary instrumentation, binary rewriting, binary code similarity detection, malware analysis, and vulnerability analysis, etc.
[0003] Researchers have designed many methods for disassembling binary files. These methods can be divided into four categories: 1) linear sweep disassembly; 2) recursive disassembly; 3) superset disassembly; 4) machine learning-based disassembly. However, disassembly is a challenging task because the compiler discards a large amount of information during the compilation process, and there are still some deficiencies in these methods. Existing disassembly algorithms have their own limitations, and the best balance has not been achieved among precision, recall, and speed, which will greatly increase the cost and complexity of applying these methods to practical problems.
[0004] How to achieve disassembly that balances precision, recall, and speed is a technical problem that needs to be solved currently. Summary of the Invention
[0005] The present invention provides a binary program disassembly method and apparatus to solve the defects existing in the prior art.
[0006] The present invention provides a binary program disassembly method, including the following steps: Obtain the original bytes of the binary program, and divide the original bytes into multiple byte code segments; Screen out target byte code segments containing valid code entry points from the multiple byte code segments, screen out a target assembly path from multiple candidate assembly paths generated by performing superset disassembly on the target byte code segments, and determine the entry instruction of the target assembly path; Use the entry instruction of the target assembly path as the starting point for recursive disassembly, and perform recursive disassembly on the target byte code segments to generate corresponding target assembly instructions.
[0007] According to the binary program disassembly method provided by the present invention, the step of screening out target byte code segments containing valid code entry points from the multiple byte code segments, screening out a target assembly path from multiple candidate assembly paths generated by performing superset disassembly on the target byte code segments, and determining the entry instruction of the target assembly path includes: Based on a pre-trained entry judgment model, screen out target byte code segments containing valid code entry points from the multiple byte code segments, and perform superset disassembly on the target byte code segments to obtain multiple candidate assembly paths; Screen the target assembly path from the multiple candidate assembly paths, and determine the entry instruction of the target assembly path.
[0008] According to a binary program disassembly method provided by the present invention, the method for screening out the target bytecode segments containing valid code entries from the multiple bytecode segments based on a pre-trained entry judgment model, and performing superset disassembly on the target bytecode segments to obtain multiple candidate assembly paths, includes: Screen out multiple target bytecode segments containing valid code entries from the multiple bytecode segments based on a pre-trained entry judgment model; Perform superset disassembly on each of the multiple target bytecode segments respectively to generate initial assembly instructions for each target bytecode segment; Group the initial assembly instructions of each target bytecode segment respectively to obtain multiple candidate assembly paths corresponding to each target bytecode segment.
[0009] According to a binary program disassembly method provided by the present invention, the method for screening out the target assembly path from the multiple candidate assembly paths and determining the entry instruction of the target assembly path includes: Screen out the target assembly path containing the real code entry instruction from the multiple candidate assembly paths based on a pre-trained path selection model; Identify the entry instruction of the target assembly path based on a pre-trained entry recognition model.
[0010] According to a binary program disassembly method provided by the present invention, the method for obtaining the original bytes of the binary program and dividing the original bytes into multiple bytecode segments includes: Obtain the original bytes of the binary program; When the length of the original bytes of the binary program is an integer multiple of the preset byte length, divide the original bytes into multiple bytecode segments; When the length of the original bytes of the binary program is not an integer multiple of the preset byte length, pad the length of the original bytes to an integer multiple of the preset byte length, and divide the padded original bytes into multiple bytecode segments.
[0011] The present invention also provides a binary program disassembly device, including the following modules: A division module, configured to obtain the original bytes of the binary program and divide the original bytes into multiple bytecode segments; A screening module, configured to screen out target bytecode segments containing valid code entry points from the multiple bytecode segments, screen out a target assembly path from multiple candidate assembly paths generated by performing superset disassembly on the target bytecode segments, and determine the entry instruction of the target assembly path; A disassembly module, configured to use the entry instruction of the target assembly path as the starting point for recursive disassembly, and perform recursive disassembly on the target bytecode segment to generate corresponding target assembly instructions.
[0012] According to a binary program disassembly device provided by the present invention, the screening module is specifically configured to: Based on a pre-trained entry judgment model, screen out target bytecode segments containing valid code entry points from the multiple bytecode segments, and perform superset disassembly on the target bytecode segments to obtain multiple candidate assembly paths; Based on the multiple candidate assembly paths, screen out a target assembly path, and determine the entry instruction of the target assembly path.
[0013] According to a binary program disassembly device provided by the present invention, the device further includes an initial disassembly module, which is specifically configured to: Based on a pre-trained entry judgment model, screen out multiple target bytecode segments containing valid code entry points from the multiple bytecode segments; Perform superset disassembly on each of the multiple target bytecode segments respectively to generate initial assembly instructions for each target bytecode segment; Group the initial assembly instructions of each target bytecode segment respectively to obtain multiple candidate assembly paths corresponding to each target bytecode segment.
[0014] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the binary program disassembly method described in any one of the above is implemented.
[0015] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the binary program disassembly method described in any one of the above is implemented.
[0016] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, the binary program disassembly method described in any one of the above is implemented.
[0017] A binary program disassembly method and device provided by the present invention obtain the original bytes of a binary program and divide the original bytes into multiple byte code segments; screen out target byte code segments containing valid code entry points from the multiple byte code segments, screen out a target assembly path from multiple candidate assembly paths generated by performing superset disassembly on the target byte code segments, and determine the entry instruction of the target assembly path; use the entry instruction of the target assembly path as the starting point for recursive disassembly, and perform recursive disassembly on the target byte code segments to generate corresponding target assembly instructions. It can be seen that the present invention first combines the screening of original bytes and superset disassembly to efficiently identify code entry points, provides useful information for subsequent instruction identification, and then accurately and efficiently restores assembly instructions through recursive disassembly on the identified code entry points, so as to achieve disassembly that takes into account speed, precision, and recall rate. Description of the Drawings
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0019] Figure 1 It is a schematic flowchart of the binary program disassembly method provided by the present invention.
[0020] Figure 2 It is a schematic flowchart of an embodiment of the binary program disassembly method provided by the present invention.
[0021] Figure 3 It is a schematic diagram of the application result of the binary program disassembly method provided by the present invention.
[0022] Figure 4 It is a schematic structural diagram of the binary program disassembly device provided by the present invention.
[0023] Figure 5 It is a schematic structural diagram of the electronic device provided by the present invention. Detailed Embodiments
[0024] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention with reference to the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.
[0025] The following combines with Figures 1 - 5 to describe a binary program disassembly method and apparatus of the present invention.
[0026] Before elaborating on the method of the present invention in detail, first, a schematic explanation of the noun terms involved in the present invention is given.
[0027] Linear scanning: It is the most intuitive disassembly algorithm. It treats all bytes in the code segment as consecutive assembly instructions and disassembles them one by one. Almost all existing disassembly tools adopt this algorithm at least partially. However, due to the existence of control flow transfers, assembly instructions are not always consecutive. Therefore, if there is data mixed in the instructions, this algorithm will generate many errors.
[0028] Recursive disassembly: It is a supplement to linear scanning. It disassembles bytes according to control flow transfers. This method mimics the behavior of the CPU, that is, it follows the control flow to obtain the next instruction. Therefore, it is usually more accurate than linear scanning. However, different from the CPU, the disassembler does not know the targets of indirect control flow transfers, including indirect calls, indirect jumps, and function returns. Therefore, recursive disassembly will stop at these instructions, resulting in a low recall rate of instructions. Disassembly tools, such as IDA and Ghidra, use heuristic rules (such as knowledge from call frame information CFI) to scan the remaining code and infer possible code entries (i.e., function entries or block entries) to assist recursive disassembly, but such rules may lead to errors.
[0029] Superset disassembly: It treats all bytes as candidate code entries and performs linear scanning disassembly to generate a superset disassembly result that completely contains the real disassembly result. Obviously, there are many pseudo-code entries in the superset. Therefore, superset disassembly solutions apply various heuristic rules to iteratively infer the possibility that each code entry is a real code entry and remove conflicting or illegal instructions. However, such algorithms are time-consuming. The number of candidate code entries is proportional to the size of the binary program. Therefore, linear scanning disassembly and the heuristic rules applied to judge candidate code entries consume a lot of time.
[0030] Machine learning-based methods: Such solutions usually use machine learning models to capture the characteristics of binary files, such as function boundaries, instruction boundaries, etc. Among them, DeepDi has achieved the best results. It also adopts superset disassembly and directly predicts legal instructions using a GNN-based neural network. However, such solutions do not follow the CPU behavior and may produce error results that never appear in rule-based solutions. For example, when given three consecutive instructions, DeepDi may predict the first and third instructions as valid instructions, while predicting the second one as an invalid instruction.
[0031] Existing disassembly algorithms all have limitations, and the best balance has not been achieved among accuracy, recall, and speed. This will greatly increase the cost and complexity of applying these methods to practical problems. Based on this, the present invention proposes a binary program disassembly method to solve at least one of the above problems.
[0032] Figure 1 It is a schematic flowchart of the binary program disassembly method provided by the present invention. As Figure 1 shown, the method includes the following: Step 100: Obtain the original bytes of the binary program and divide the original bytes into multiple byte code segments.
[0033] Specifically, first, the steps of obtaining the original bytes of the binary program in Step 100 and dividing the original bytes into multiple byte code segments will be specifically described, including: Step 110: Obtain the original bytes of the binary program.
[0034] Step 120: When the length of the original bytes of the binary program is an integer multiple of the preset byte length, divide the original bytes into multiple byte code segments.
[0035] Step 130: When the length of the original bytes of the binary program is not an integer multiple of the preset byte length, pad the length of the original bytes to an integer multiple of the preset byte length, and divide the padded original bytes into multiple byte code segments.
[0036] Specifically, for a group of consecutive original bytes (such as a binary program or a part of its bytes), divide it into multiple segments, and each segment can contain, for example, 512 consecutive bytes, with padding if necessary.
[0037] Step 200: Screen out the target byte code segments containing valid code entrances from the multiple byte code segments, screen out the target assembly path from the multiple candidate assembly paths generated by performing superset disassembly on the target byte code segments, and determine the entry instruction of the target assembly path.
[0038] Specifically, Step 200 includes: Step 210: Screen out the target byte code segments containing valid code entrances from the multiple byte code segments based on a pre-trained entry judgment model, and perform superset disassembly on the target byte code segments to obtain multiple candidate assembly paths.
[0039] Step 210 specifically includes: Step 211: Screen out multiple target byte code segments containing valid code entrances from the multiple byte code segments based on a pre-trained entry judgment model.
[0040] Step 212: Perform superset disassembly on each of the multiple target bytecode segments respectively to generate initial assembly instructions for each target bytecode segment.
[0041] Step 213: Group the initial assembly instructions of each target bytecode segment respectively to obtain multiple candidate assembly paths corresponding to each target bytecode segment.
[0042] Step 220: Screen to obtain a target assembly path based on the multiple candidate assembly paths, and determine the entry instruction of the target assembly path.
[0043] Step 220 specifically includes: Step 221: Screen out a target assembly path containing a real code entry instruction from the multiple candidate assembly paths based on a pre-trained path selection model.
[0044] Step 222: Identify the entry instruction of the target assembly path based on a pre-trained entry recognition model.
[0045] Specifically, in this embodiment, first, a model, that is, an entry judgment model, is used to infer whether a segment contains a valid code entry. Then, superset disassembly is only applied to the segments containing valid code entries, thus avoiding huge time consumption. The result of superset disassembly, that is, the initial assembly instructions, is grouped into assembly paths, each path contains consecutive instructions, and no two paths contain each other. Next, in this embodiment, a second model, that is, a path selection model, is used to select a path containing a real code entry instruction. For the selected path, in this embodiment, a third model, that is, an entry recognition model, is used to identify the entry instruction. These entry instructions are then used as the starting point for recursive disassembly to generate complete target assembly instructions.
[0046] It should be noted that, in order to achieve a lightweight solution on the premise of fully ensuring the effectiveness of the machine learning model, the following strategies are adopted in data and model design: 1. For the entry judgment model, a bytecode segment containing one or more code entries is marked as 1, indicating that the bytecode segment contains a code entry. A bytecode segment that does not contain any code entry is marked as 0, indicating that they do not contain a code entry. Since this is a sequence-level binary classification task, capturing a small amount of useful information from the bytecode segment can guide the model to correctly obtain the correct result, and the machine learning model can efficiently complete this task.
[0047] 2. For the path selection model, if all the instructions in an assembly path do not conflict with any instructions in the real data, then this assembly path is considered correct. Otherwise, this assembly path is incorrect, that is, there is a partial address overlap between the instructions in the incorrect assembly path and the real data. Since the length of the bytecode segment is short, the candidate assembly paths are also short, and the assembly paths that do not conflict with any instructions in the real data are significantly different in assembly semantics from other incorrect assembly paths. Therefore, the machine learning model can also efficiently complete this task. The use of the path selection model in the present invention for path screening has many advantages compared with directly implementing it with computer commands. For complex binary programs, directly implementing path screening with computer commands may encounter many difficulties. For example, it is difficult to handle situations such as indirect jumps, function calls, and exception handling. In terms of the result quality, directly implementing path screening with computer commands may lead to incorrect results due to imperfect rules. For example, data may be misrecognized as code, or illegal instructions may be misrecognized as legal instructions. The path selection model can automatically discover patterns and rules in the data by learning a large amount of data, thereby improving the accuracy of path screening. In summary, considering various aspects such as implementation difficulty, code readability and maintainability, the ability to process complex data, adaptability and scalability, accuracy, and recall rate, the AI model can better process complex binary programs, improve the accuracy and recall rate of path screening, and at the same time has better adaptability and scalability, and can better meet the needs of practical applications.
[0048] 3. For the entry recognition model, the instructions that are function entries in the selected assembly paths are marked as 1, and the remaining instructions are marked as 0. Since the final paths are selected from the shorter candidate assembly paths, under this constraint, the instructions that are function entries are significantly different in assembly semantics from the instructions that are not function entries, and the machine learning model can efficiently complete this task.
[0049] 4. The embodiments of the present invention use a bidirectional GRU model with 1.8 million parameters to complete each task. The powerful bidirectional temporal model can better pay attention to the bidirectional close-range sequence information, and since the segments used are relatively short, the model will not lose the long-range sequence information. Such a design conforms to the basic characteristics of bytecode and assembly sequences. The 1.8 million parameters also ensure the lightweight of the model and ensure the rapid execution of the entire process. It should be noted that in the present invention, the use of the three models can better save resources compared with the existing machine learning-based disassembly, and has more advantages compared with directly implementing without using models through computer languages.
[0050] ①Improve efficiency and accuracy: The three models each perform their own functions and handle different tasks respectively. After pre-training, the models can quickly screen out the target bytecode segments containing valid code entry points, screen out the target assembly paths containing the real code entry instructions and identify their entry instructions. Compared with traditional manual rules or heuristic methods, they can process a large amount of complex data more efficiently and accurately. Especially in the big data environment, the advantages of the models are more significant.
[0051] ②Higher degree of automation: The models can automatically learn and capture the patterns and features in the data, and continuously optimize their own parameters and structures through the training data. When facing new data, they can automatically identify and process it without manually writing complex rules and logics, thus greatly improving the automation level of the system, reducing the need for manual intervention, and also reducing the probability of errors.
[0052] ③Stronger adaptability: The designs of the three models can be adjusted and optimized according to different application scenarios and data sets. If the characteristics of the data set change or new requirements emerge, the models can be retrained or fine-tuned to better adapt to the new situation. This flexibility enables the system to better handle various complex scenarios and requirements.
[0053] ④Good scalability: With the growth of data volume and the continuous improvement of algorithms, the models can be continuously expanded and upgraded. New data can be used to further optimize the performance of the models, and new algorithms can be integrated into the existing model framework, thus continuously improving the overall performance and functions of the system. Moreover, the structure of the models can be easily expanded by adding new models or modules to handle new tasks or requirements.
[0054] Step 300: Use the entry instruction of the target assembly path as the starting point for recursive disassembly to generate target assembly instructions.
[0055] In the embodiments of the present invention, by combining superset disassembly, recursive disassembly and machine learning models at different stages, a disassembly method that takes into account speed, precision and recall rate is realized; three very small but effective machine learning models are used, and the code entry recognition task is completed through a more intuitive learning-superset-learning-recursive algorithm application model. This method not only overcomes the limitations of superset disassembly and recursive disassembly, but also ensures the execution speed of disassembly; this method performs excellently on real-world binary programs, large binary programs and CFI-obfuscated binary programs. Therefore, it is not limited to a certain special disassembly scenario and has the potential for application in a wider range of scenarios.
[0056] The above is a description of the steps of the binary program disassembly method provided by the present invention. From the description of the above steps, it can be seen that according to the binary program disassembly method provided by the present invention, by obtaining the original bytes of the binary program and dividing the original bytes into multiple byte code segments; screening out the target byte code segments containing valid code entry points from the multiple byte code segments, screening out the target assembly path from the multiple candidate assembly paths generated by performing superset disassembly on the target byte code segments, and determining the entry instruction of the target assembly path; using the entry instruction of the target assembly path as the starting point of recursive disassembly, performing recursive disassembly on the target byte code segment to generate the corresponding target assembly instruction. It can be seen that the present invention first combines the screening of the original bytes and superset disassembly to efficiently identify the code entry, provides useful information for subsequent instruction recognition, and then accurately and efficiently restores the assembly instructions by performing recursive disassembly on the identified code entry, so as to achieve disassembly that takes into account speed, precision, and recall.
[0057] Figure 2 is a schematic flowchart of an embodiment of the binary program disassembly method provided by the present invention. The following combines Figure 2 to give a complete description of the binary program disassembly method provided by the present invention.
[0058] As Figure 2 shown, the implementation process of the embodiment of the present invention is divided into three stages (identifying and determining the function stage, function entry identification stage, block entry identification stage).
[0059] In the stage of identifying and determining the function, the embodiment of the present invention uses information directly existing in the binary program such as the program entry point and the external table to identify some determined function entry points, and performs recursive disassembly starting from these function entry points to obtain a part of the determined assembly instructions.
[0060] In the function entry identification stage, the embodiment of the present invention divides the remaining unassembled bytes of the binary program into multiple byte code segments of 512 bytes, such as byte code segments [100110], [010101], [101101], and uses the function entry judgment model to identify which segments may contain function entry points. Continue to refer to Figure 2, [100110] is the bytecode segment that definitely contains the function entry point. Supersets disassembly is only applied to this segment, and three candidate disassembly paths, Trace 1, Trace 2, and Trace 3, are generated based on this segment. Next, the path selection model is used to identify the most likely disassembly path for each bytecode segment. In this embodiment, Trace 2 is determined as the target disassembly path. Then, the function entry identification model restores the function entry on Trace 2. Finally, these identified function entries are sorted according to the model confidence, and recursive disassembly starts from the function entry with high confidence. If the disassembly instructions disassembled starting from a certain function entry do not conflict with the previously determined disassembly instructions, this function entry will be regarded as the determined function entry, and the corresponding disassembly instructions will be regarded as the determined disassembly instructions; otherwise, this function entry will be skipped.
[0061] In the block entry identification stage, the embodiment of the present invention divides the remaining bytecode segments into multiple 512-byte bytecode segments again, such as bytecode segments [100110], [010101], [101101], and extracts all the bytecode segments immediately following indirect jumps, such as bytecode segment [100110]. Then, supersets disassembly is used for this bytecode segment, and two candidate disassembly paths, Trace 1 and Trace 2, are generated based on this segment. Then, the correct target disassembly path Trace 2 is selected through the path selection model. The block entry point is restored on the correct target disassembly path Trace 2, and recursive disassembly starts from these block entry points. Similarly, only the results that do not conflict with the previously determined function entries and disassembly instructions will be considered as determined results. Because recursive disassembly may encounter new indirect jump instructions, this stage will iterate until there are no unrecognized bytes.
[0062] After the three stages are completed, the present invention outputs the finally determined function entries and disassembly instructions.
[0063] Those skilled in the art can easily understand that the above description is only the preferred embodiment of the present invention. Without departing from the principle of the present invention, several improvements and refinements can be made. For example, although this embodiment uses the program entry point and the external table as the information for determining the function entry, other information or no such information can be used as auxiliary information. Similarly, although specific compilers and optimization options are used in this embodiment, other compilers and optimization options can be used. In addition, although a specific network structure is used here, other types of network structures can be used.
[0064] In a specific scenario, Figure 3 is the schematic diagram of the application result of the binary program disassembly method provided by the present invention, as Figure 3As shown in the figure, the method provided by the embodiments of the present invention can help identify the function entry and the assembly instruction result of a section of bytecode. Among them, the red ones are the function entry instructions, and the black instructions are non-function entry instructions.
[0065] The binary program disassembly method provided by the embodiments of the present invention first combines superset disassembly and a machine learning model to efficiently identify the code entry, providing useful information for subsequent instruction identification. Then, by performing recursive disassembly on the identified code entry, the assembly instructions are accurately and efficiently restored, thus achieving disassembly that takes into account speed, precision, and recall. This method has extremely strong universality. It not only shows remarkable capabilities on real-world binary files, but also performs well on binary files with a large file size and binary files with confused function call frame information. The method of the present invention is superior to the existing state-of-the-art solutions in these scenarios, showing great application potential and practical value.
[0066] The binary program disassembly device provided by the present invention will be described below. The binary program disassembly device described below can be correspondingly referred to the binary program disassembly method described above.
[0067] Figure 4 is a schematic structural diagram of the binary program disassembly device provided by the present invention. As Figure 4 shown, the binary program disassembly device provided by the present invention includes: A partitioning module 401, configured to obtain the original bytes of the binary program and partition the original bytes into multiple bytecode segments; A screening module 402, configured to screen out the target bytecode segments containing valid code entries from the multiple bytecode segments, screen out the target assembly paths from the multiple candidate assembly paths generated by performing superset disassembly on the target bytecode segments, and determine the entry instructions of the target assembly paths; A disassembly module 403, configured to use the entry instructions of the target assembly path as the starting point of recursive disassembly, and perform recursive disassembly on the target bytecode segments to generate corresponding target assembly instructions.
[0068] The binary program disassembly device provided by the present invention obtains the original bytes of the binary program and divides the original bytes into multiple byte code segments; filters out the target byte code segments containing valid code entry points from the multiple byte code segments, screens out the target disassembly paths from the multiple candidate disassembly paths generated by performing superset disassembly on the target byte code segments, and determines the entry instructions of the target disassembly paths; uses the entry instructions of the target disassembly paths as the starting point for recursive disassembly, and performs recursive disassembly on the target byte code segments to generate corresponding target disassembly instructions. It can be seen that the present invention first combines the screening of original bytes and superset disassembly to efficiently identify code entry points, provides useful information for subsequent instruction identification, and then accurately and efficiently restores disassembly instructions through recursive disassembly on the identified code entry points, so as to achieve disassembly that takes into account speed, precision, and recall rate.
[0069] Based on the above embodiment, in this embodiment, the screening module 402 is specifically configured to: Filter out the target byte code segments containing valid code entry points from the multiple byte code segments based on a pre-trained entry judgment model, and perform superset disassembly on the target byte code segments to obtain multiple candidate disassembly paths; Filter out the target disassembly paths from the multiple candidate disassembly paths and determine the entry instructions of the target disassembly paths.
[0070] Based on the above embodiment, in this embodiment, the device further includes an initial disassembly module, which is specifically configured to: Filter out multiple target byte code segments containing valid code entry points from the multiple byte code segments based on a pre-trained entry judgment model; Perform superset disassembly on each of the multiple target byte code segments respectively to generate initial disassembly instructions for each target byte code segment; Group the initial disassembly instructions of each target byte code segment respectively to obtain multiple candidate disassembly paths corresponding to each target byte code segment.
[0071] Based on the above embodiment, in this embodiment, the device further includes an identification module, which is specifically configured to: Filter out the target disassembly paths containing real code entry instructions from the multiple candidate disassembly paths based on a pre-trained path selection model; Identify the entry instructions of the target disassembly paths based on a pre-trained entry identification model.
[0072] Based on the above embodiment, in this embodiment, the division module 401 is specifically configured to: Obtain the original bytes of the binary program; When the original byte length of the binary program is an integer multiple of a preset byte length, divide the original bytes into multiple byte code segments; When the original byte length of the binary program is not an integer multiple of the preset byte length, pad the original byte length to an integer multiple of the preset byte length, and divide the padded original bytes into multiple byte code segments.
[0073] Figure 5 An example of a schematic diagram of the physical structure of an electronic device is shown as Figure 5 shown. The electronic device can be a robot or other electronic device. The electronic device may include: a processor 510, a communication interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call the logical instructions in the memory 530 to execute the binary program disassembly method, including: Obtain the original bytes of the binary program and divide the original bytes into multiple byte code segments; Select target byte code segments containing valid code entry points from the multiple byte code segments, select a target assembly path from the multiple candidate assembly paths generated by performing superset disassembly on the target byte code segments, and determine the entry instruction of the target assembly path; Use the entry instruction of the target assembly path as the starting point for recursive disassembly, and perform recursive disassembly on the target byte code segments to generate corresponding target assembly instructions.
[0074] In addition, when the logical instructions in the above-mentioned memory 530 can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical disks, etc., which can store program codes.
[0075] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the binary program disassembly method provided by each of the above methods, including: Obtain the original bytes of the binary program and divide the original bytes into multiple byte code segments; Select a target byte code segment containing a valid code entry from the multiple byte code segments, screen a target assembly path from the multiple candidate assembly paths generated by performing superset disassembly on the target byte code segment, and determine the entry instruction of the target assembly path; Use the entry instruction of the target assembly path as the starting point for recursive disassembly, and perform recursive disassembly on the target byte code segment to generate corresponding target assembly instructions.
[0076] On another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the binary program disassembly method provided by each of the above methods, including: Obtain the original bytes of the binary program and divide the original bytes into multiple byte code segments; Select a target byte code segment containing a valid code entry from the multiple byte code segments, screen a target assembly path from the multiple candidate assembly paths generated by performing superset disassembly on the target byte code segment, and determine the entry instruction of the target assembly path; Use the entry instruction of the target assembly path as the starting point for recursive disassembly, and perform recursive disassembly on the target byte code segment to generate corresponding target assembly instructions.
[0077] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0078] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0079] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A binary program disassembly method, characterized in that: include: Obtaining original bytes of a binary program, and dividing the original bytes into a plurality of bytecode segments; Filtering out a target bytecode segment containing a valid code entry from the multiple bytecode segments, filtering out a target assembly path from multiple candidate assembly paths generated by superset disassembly of the target bytecode segment, and determining an entry instruction of the target assembly path; The entry instruction of the target assembly path is used as the starting point of recursive disassembly, and the target bytecode segment is recursively disassembled to generate the corresponding target assembly instruction.
2. The binary program disassembly method according to claim 1, characterized in that: The step of selecting a target bytecode segment containing a valid code entry from the multiple bytecode segments, selecting a target assembly path from multiple candidate assembly paths generated by superset disassembly of the target bytecode segment, and determining an entry instruction of the target assembly path includes: Based on the pre-trained entry judgment model, a target bytecode segment containing a valid code entry is screened out from the multiple bytecode segments, and superset disassembly is performed on the target bytecode segment to obtain multiple candidate assembly paths; A target assembly path is obtained by screening based on the multiple candidate assembly paths, and an entry instruction of the target assembly path is determined.
3. The binary program disassembly method according to claim 2, characterized in that: The pre-trained entry judgment model selects a target bytecode segment containing a valid code entry from the multiple bytecode segments, and performs superset disassembly on the target bytecode segment to obtain multiple candidate assembly paths, including: Filtering out a plurality of target bytecode segments containing valid code entries from the plurality of bytecode segments based on a pre-trained entry judgment model; Performing superset disassembly on each target bytecode segment of the multiple target bytecode segments to generate initial assembly instructions for each target bytecode segment; The initial assembly instructions of each target bytecode segment are grouped respectively to obtain a plurality of candidate assembly paths corresponding to each target bytecode segment.
4. The binary program disassembly method according to claim 2, characterized in that: The step of obtaining a target assembly path by screening the plurality of candidate assembly paths and determining an entry instruction of the target assembly path includes: Filtering a target assembly path containing a real code entry instruction from the plurality of candidate assembly paths based on a pre-trained path selection model; The entry instruction of the target assembly path is obtained based on the pre-trained entry recognition model identification.
5. The binary program disassembly method according to claim 1, characterized in that: The obtaining of the original bytes of the binary program and dividing the original bytes into a plurality of bytecode segments includes: Obtaining raw bytes of the binary program; When the original byte length of the binary program is an integer multiple of the preset byte length, dividing the original bytes into a plurality of byte code segments; When the original byte length of the binary program is not an integer multiple of the preset byte length, the original byte length is padded to an integer multiple of the preset byte length, and the padded original bytes are divided into a plurality of byte code segments.
6. A binary program disassembly device, characterized in that: include: A partitioning module, used for obtaining original bytes of a binary program and partitioning the original bytes into a plurality of bytecode segments; A screening module is used to screen out a target bytecode segment containing a valid code entry from the multiple bytecode segments, screen out a target assembly path from multiple candidate assembly paths generated by superset disassembly of the target bytecode segment, and determine an entry instruction of the target assembly path; The disassembly module is used to use the entry instruction of the target assembly path as the starting point of recursive disassembly, recursively disassemble the target bytecode segment, and generate corresponding target assembly instructions.
7. The binary program disassembly device according to claim 6, characterized in that: The screening module is specifically used for: Based on the pre-trained entry judgment model, a target bytecode segment containing a valid code entry is screened out from the multiple bytecode segments, and superset disassembly is performed on the target bytecode segment to obtain multiple candidate assembly paths; A target assembly path is obtained by screening based on the multiple candidate assembly paths, and an entry instruction of the target assembly path is determined.
8. The binary program disassembly device according to claim 7, characterized in that: The device also includes an initial disassembly module, which is specifically used for: Filtering out a plurality of target bytecode segments containing valid code entries from the plurality of bytecode segments based on a pre-trained entry judgment model; Performing superset disassembly on each target bytecode segment of the multiple target bytecode segments to generate initial assembly instructions for each target bytecode segment; The initial assembly instructions of each target bytecode segment are grouped respectively to obtain a plurality of candidate assembly paths corresponding to each target bytecode segment.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the binary program disassembly method according to any one of claims 1 to 5 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the binary program disassembly method according to any one of claims 1 to 5 is implemented.