Can Zhang

26 papers Journal 24Unranked 2
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Internet Things J.
Xiangbo Yuan, Peng Jiang, Zhuo Chen, Can Zhang, Feng Gao, Liehuang Zhu
2025 J jnl
IEEE Trans. Inf. Forensics Secur.
Hanqi Zhang, Yandong Zheng, Chang Xu, Liehuang Zhu, Can Zhang
2024 J jnl
IEEE Trans. Inf. Forensics Secur.
Zhuo Chen, Liehuang Zhu, Peng Jiang, Can Zhang, Feng Gao, Fuchun Guo
2023 J jnl
IEEE Trans. Computers
Liehuang Zhu, Qi Liu, Zhuo Chen, Can Zhang, Feng Gao, Zhongliang Yang
2023 J jnl
IEEE Trans. Ind. Informatics
Can Zhang, Liehuang Zhu, Chang Xu
2023 J jnl
IEEE Multim.
Yao Xiao, Lei Xu, Can Zhang, Liehuang Zhu, Yan Zhang
2023 J jnl
J. Netw. Comput. Appl.
Can Zhang, Liehuang Zhu, Chang Xu, Zijian Zhang, Rongxing Lu
2023 J jnl
IEEE Trans. Sustain. Comput.
Chang Xu, Zijian Chan, Liehuang Zhu, Can Zhang, Rongxing Lu, Yunguo Guan
2023 J jnl
IEEE Internet Things J.
Yan Wu, Can Zhang, Liehuang Zhu
2023 J jnl
Peer Peer Netw. Appl.
Chang Xu, Run Yin, Liehuang Zhu, Can Zhang, Kashif Sharif
2022 J jnl
IEEE Trans. Veh. Technol.
Can Zhang, Liehuang Zhu, Chang Xu, Kashif Sharif, Rongxing Lu, Yupeng Chen
2022 J jnl
IEEE Consumer Electron. Mag.
Can Zhang, Liehuang Zhu, Chang Xu
2022 J jnl
IEEE Commun. Surv. Tutorials
Zhuo Chen, Liehuang Zhu, Peng Jiang, Can Zhang, Feng Gao, Jialing He, Dawei Xu, Yan Zhang
2022 J jnl
IEEE Internet Things J.
Chang Xu, Run Yin, Liehuang Zhu, Chuan Zhang, Can Zhang, Yupeng Chen, Kashif Sharif
2021 J jnl
Peer-to-Peer Netw. Appl.
Chang Xu, Lan Yu, Liehuang Zhu, Can Zhang
2021 conf
CNCERT
Yujia Tang, Chang Xu, Can Zhang, Yan Wu, Liehuang Zhu
2021 conf
WASA (3)
Chang Xu, Lan Yu, Liehuang Zhu, Can Zhang
2021 J jnl
Peer-to-Peer Netw. Appl.
Chang Xu, Jiachen Wang, Liehuang Zhu, Kashif Sharif, Chuan Zhang, Can Zhang
2021 J jnl
IEEE Trans. Veh. Technol.
Can Zhang, Liehuang Zhu, Chang Xu, Kashif Sharif
2021 J jnl
Comput. Stand. Interfaces
Can Zhang, Chang Xu, Kashif Sharif, Liehuang Zhu
2020 J jnl
IEEE Netw.
Feng Gao, Liehuang Zhu, Keke Gai, Can Zhang, Sheng Liu
2020 J jnl
Comput. Secur.
Chuan Zhang, Chang Xu, Liehuang Zhu, Yanwei Li, Can Zhang, Huishu Wu
2020 J jnl
IEEE Trans. Veh. Technol.
Can Zhang, Liehuang Zhu, Chang Xu, Chuan Zhang, Kashif Sharif, Huishu Wu, Hannes Westermann
2020 J jnl
Multim. Tools Appl.
Kexin Shi, Liehuang Zhu, Can Zhang, Lei Xu, Feng Gao
2020 J jnl
Inf. Sci.
Can Zhang, Liehuang Zhu, Chang Xu, Kashif Sharif, Chuan Zhang, Ximeng Liu
2019 J jnl
IEEE Internet Things J.
Chang Xu, Yayun Si, Liehuang Zhu, Chuan Zhang, Kashif Sharif, Can Zhang
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False