Ioana Ocnarescu

12 papers A 2B 3Misc 1Unranked 6
YearRankTypeTitle / Venue / Authors
2023 conf
ICSR (2)
Xiaoxuan Hei, Valentine Denis, Pierre-Henri Orefice, Alia Afyouni, Paul Laborde, Damien Legois, Ioana Ocnarescu, Margarita Anastassova, Adriana Tapus
2022 conf
ICSR (2)
Mégane Sartore, Ioana Ocnarescu, Louis-Romain Joly, Stéphanie Buisine
2022 B conf
RO-MAN
Alia Afyouni, Ioana Ocnarescu, Isabelle Cossin, Emna Kamoun, Alexandre Mazel, Charles Fattal
2022 conf
CSCI
Hazar Zilelioglu, Ioana Ocnarescu, Ghazaleh Khodabandelou, Abdelghani Chibani, Clément Bataille, Jérôme Mlynarczyk, Yacine Amirat, Solène Le Bars
2022 A conf
Conference on Designing Interactive Systems
Dominique Deuff, Isabelle Milleville-Pennel, Ioana Ocnarescu, Dora Garcin, Corentin Aznar, Siméon Capy, Shohei Hagane, Pablo Felipe Osorio Marin, Enrique Coronado Zuniga, Liz Rincon Ardila, Gentiane Venture
2019 B conf
ICSR
Ioana Ocnarescu, Isabelle Cossin
2018 Misc conf
NordiCHI
Mohammad Obaid, Kirsikka Kaipainen, Aino Ahtinen, Ioana Ocnarescu
2017 B conf
ICSR
Ioana Ocnarescu, Isabelle Cossin
2014 conf
Erog'IA
Carine Lallemand, Kerstin Bongard-Blanchy, Ioana Ocnarescu
2013 conf
DPPI
Silvia Grimaldi, Steven Fokkinga, Ioana Ocnarescu
2012 A conf
Conference on Designing Interactive Systems
Majken Kirkegaard Rasmussen, Natalie Lehoux, Ioana Ocnarescu, Peter Gall Krogh
2011 conf
DPPI
Ioana Ocnarescu, Frédérique Pain, Carole Bouchard, Améziane Aoussat, Dominique Sciamma
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False