计算机工程 ›› 2013, Vol. 39 ›› Issue (8): 77-82.doi: 10.3969/j.issn.1000-3428.2013.08.016

• 体系结构与软件技术 • 上一篇    下一篇

基于自动路径驱动的动态控制流恢复算法

张 平,李清宝,崔 晨   

  1. (解放军信息工程大学一系,郑州 450002)
  • 收稿日期:2012-03-27 出版日期:2013-08-15 发布日期:2013-08-13
  • 作者简介:张 平(1969-),女,副教授、博士,主研方向:软件工程,软件测试;李清宝,教授、博士;崔 晨,硕士研究生
  • 基金项目:
    国家“863”计划基金资助项目(2009AA01ZA434)

Dynamic Control Flow Recovery Algorithm Based on Automatic Path Driven

ZHANG Ping, LI Qing-bao, CUI Chen   

  1. (No.1 Department, PLA Information Engineering University, Zhengzhou 450002, China)
  • Received:2012-03-27 Online:2013-08-15 Published:2013-08-13

摘要: 动态控制流恢复方法存在路径覆盖不全的问题。为解决该问题,提出一种基于自动路径驱动的控制流恢复算法。在可控的模拟调试环境中动态执行并分析二进制程序,通过修改CPU程序计数器的值,使驱动程序执行在当前输入条件下无法访问的程序路径,从而构建控制流图。基于该算法,设计实现自动路径驱动控制流恢复系统。测试结果表明,该算法能够较全面地发掘程序执行路径,与传统动态执行算法和交互式反汇编器相比,能有效提高恢复控制流图的覆盖率。

关键词: 控制流图, 路径驱动, 动态分析, 二进制程序, 模拟调试环境, 程序计数器

Abstract: To solve the problem in dynamic control flow reconstruction that not all program execution paths can be explored, an algorithm based on execution path driven is presented. The main idea of this algorithm is to run the binary program in a controllable instrument environment, and drives it to execute the program paths which can’t be explored under current input set by modifying the value of Program Counter(PC), so that Control Flow Graph(CFG) can be reconstructed. Based on this algorithm, a dynamic path drive control flow recovery system is designed and implemented. Experimental results illustrate that this algorithm is effective in exploring execution paths. Compared with traditional dynamic algorithm and Interactive Disassembler(IDA), the coverage of CFG reconstructed by this algorithm is higher.

Key words: Control Flow Graph(CFG), path driven, dynamic analysis, binary program, simulation instrument environment, Program Counter(PC)

中图分类号: