计算机科学 ›› 2026, Vol. 53 ›› Issue (7): 406-413.doi: 10.11896/jsjkx.250600072
刘译聪1, 米庆荣2, 耿洋洋2, 麻荣宽2, 贾岩3, 曹琰1
LIU Yicong1, MI Qingrong2, GENG Yangyang2, MA Rongkuan2, JIA Yan3, CAO Yan1
摘要: VxWorks固件广泛应用于航空航天、工业控制、军事装备等关键领域。然而,为了满足安全性及体积优化需求,固件发布版本中的符号表常被剥离,这显著增加了逆向工程与安全分析中函数语义理解的难度。对此,设计并实现了VxSymRe——一种面向VxWorks固件的自动化函数符号恢复系统。该系统首先利用完整ELF文件及目标文件提取VxWorks函数样本,进而构建多版本、跨架构及多编译器组合的VxWorks函数特征向量库。在固件分析阶段,自动化预处理流程可识别固件的版本、体系架构与加载基址,进而明确函数边界。随后,基于语义导向图构建函数表示,借助图神经网络生成固定维度的特征向量,并通过余弦相似度完成函数符号匹配。实验结果显示:建库方面,采用ELF与目标文件联合构建策略后,函数样本总数相较于仅使用ELF文件提升42.49%;预处理方面,VxSymRe能够正确处理来自不同厂商且配置各异的固件;符号恢复方面,VxSymRe在3个不同测试样本上正确恢复的函数符号数量分别是对比方法的20.86倍、17.96倍和118.2倍。
中图分类号:
| [1]HAMBARDE P,VARMA R,JHA S.The survey of real timeoperating system:RTOS [C]//Proceedings of the 2014 International Conference on Electronic Systems,Signal Processing and Computing Technologies.New York:IEEE,2014:34-39. [2]ZHANG Z,LV Z,MO J,NIU S.Vulnerabilities analysis and solution of VxWorks [C]//Proceedings of the 2nd International Conference on Teaching and Computational Science.Paris:Atlantis Press,2014:94-97. [3]Armis.Urgent/11 [EB/OL].[2025-05-24].https://www.armis.com/research/urgent-11/. [4]HUANG J,YANG K,WANG G,et al.TaiE:Function identification for monolithic firmware [C]//Proceedings of the 32nd IEEE/ACM International Conference on Program Comprehension.New York:IEEE/ACM,2024:403-414. [5]ZHU W Z,YU Z,WANG J S,et al.Dive into VxWorks-Based IoT device:Debug the undebugable device [C]//Proceedings of Black Hat Asia 2019.2019. [6]CHEN L,CAI Q,MA Z,et al.Sfuzz:Slice-based fuzzing for real-time operating systems [C]//Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security.New York:ACM,2022:485-498. [7]Wind River.VxWorks:Industry Leading RTOS for EmbeddedSystems [EB/OL].(2025-05-24)[2025-05-24].https://www.windriver.com/products/vxworks. [8]SÁNCHEZ-GORDÓN M,COLOMO-PALACIOS R.Security as culture:a systematic literature review of DevSecOps [C]//Proceedings of the IEEE/ACM 42nd International Conference on Software Engineering Workshops.New York:IEEE/ACM,2020:266-269. [9]LU H J,MATZ M,HUBICKA J,et al.System V Application Binary Interface:AMD64 Architecture Processor Supplement [EB/OL].https://raw.githubusercontent.com/wiki/hjl-tools/x86-psabi/x86-64-psABI-1.0.pdf. [10]GAO J,YANG X,FU Y,et al.Vulseeker-Pro:Enhanced semantic learning based binary vulnerability seeker with emulation [C]//Proceedings of the 2018 26th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering.New York:ACM,2018:803-808. [11]XU X,LIU C,FENG Q,et al.Neural network-based graph embedding for cross-platform binary code similarity detection [C]//Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security.New York:ACM,2017:363-376. [12]GAO J,YANG X,FU Y,et al.Vulseeker:A semantic learning based vulnerability seeker for cross-platform binary [C]//Proceedings of the 33rd ACM/IEEE International Conference on Automated Software Engineering.New York:ACM/IEEE,2018:896-899. [13]MASSARELLI L,DI LUNA G A,PETRONI F,et al.Investigating graph embedding neural networks with unsupervised features extraction for binary analysis [C]//Proceedings of the 2nd Workshop on Binary Analysis Research(BAR).New York:IEEE,2019:1-11. [14]LI Y,GU C,DULLIEN T,et al.Graph matching networks for learning the similarity of graph structured objects [C]//Proceedings of the 36th International Conference on Machine Learning(ICML).PMLR,2019:3835-3845. [15]HE H,LIN X,WENG Z,et al.Code is not natural language:Unlock the power of semantics-oriented graph representation for binary code similarity detection [C]//Proceedings of the 33rd USENIX Security Symposium(USENIX Security 24).Philadelphia:USENIX Association,2024. [16]SU Z,XU X,HUANG Z,et al.Source code foundation models are transferable binary analysis knowledge bases [C]//Procee-dings of the Thirty-eighth Annual Conference on Neural Information Processing Systems(NeurIPS).New York:NeurIPS,2024. [17]SCHÜTZE H,MANNING C D,RAGHAVAN P.Introduction to Information Retrieval [M].Cambridge:Cambridge University Press,2008:234-265. [18]MASSARELLI L,DI LUNA G A,PETRONI F,et al.SAFE:Self-attentive function embeddings for binary similarity [C]//Proceedings of Detection of Intrusions and Malware,and Vulnerability Assessment(DIMVA 2019).Cham:Springer,2019:309-329. [19]PEI K,ZHOU X,YANG J,et al.Learning approximate execution semantics from traces for binary function similarity [J].IEEE Transactions on Software Engineering,2023,49(4):2776-2790. [20]LI Y,GU C,DULLIEN T,et al.Graph matching networks for learning the similarity of graph structured objects [C]//Proceedings of the 36th International Conference on Machine Learning(ICML).PMLR,2019:3835-3845. [21]ReFirm Labs.Binwalk:Firmware analysis tool [EB/OL].(2025-05-24)[2025-05-24].https://github.com/ReFirmLabs/binwalk. [22]ZHU R,ZHANG B,MAO J,et al.A methodology for determining the image base of ARM-based industrial control system firmware [J].International Journal of Critical Infrastructure Protection,2017,16:26-35. [23]National Security Agency.Ghidra:Software reverse engineering(SRE) framework [EB/OL].(2019-03-05)[2025-05-24].https://ghidra-sre.org/. [24]GNU Project.objdump:Display information from object files[EB/OL].(2025-05-24)[2025-05-24].https://sourceware.org/binutils/docs/binutils/objdump.html. |
|
||