Iole Moccagatta

15 papers A* 1A 2B 1C 1Misc 1Journal 5Unranked 4
YearRankTypeTitle / Venue / Authors
2024 conf
MIPR
Ryan Metcalfe, Garth Long, Charlie L. Wang, Iole Moccagatta
2017 B conf
ICIP
Zhipin Deng, Iole Moccagatta
2008 A conf
ICME
Tong Gan, Antoine Dejonghe, Gregory Lenoir, Kristof Denolf, Gauthier Lafruit, Iole Moccagatta
2008 J jnl
EURASIP J. Wirel. Commun. Netw.
Xin Ji, Sofie Pollin, Gauthier Lafruit, Iole Moccagatta, Antoine Dejonghe, Francky Catthoor
2007 conf
ICASSP (2)
Xin Ji, Sofie Pollin, Gauthier Lafruit, Iole Moccagatta, Antoine Dejonghe, Francky Catthoor
2007 A conf
ICME
Tong Gan, Kristof Denolf, Gauthier Lafruit, Iole Moccagatta, Antoine Dejonghe, Gregory Lenoir
2007 conf
EUSIPCO
Xin Ji, Sofie Pollin, Gauthier Lafruit, Iole Moccagatta, Antoine Dejonghe, Francky Catthoor
2006 A* conf
ACM Multimedia
Iole Moccagatta
2000 J jnl
IEEE J. Sel. Areas Commun.
Iole Moccagatta, Salma Soudagar, Jie Liang, Homer H. Chen
1999 J jnl
Signal Process. Image Commun.
Raj Talluri, Iole Moccagatta, Yashoda Nag, Gene Cheung
1998 C conf
MMSP
Iole Moccagatta, Shankar L. Regunathan, Osama K. Al-Shaykh, Homer H. Chen
1997 J jnl
Int. J. Imaging Syst. Technol.
Iole Moccagatta, Raj Talluri
1995 Misc conf
ICASSP
Iole Moccagatta, Murat Kunt
1994 conf
ICIP (3)
Iole Moccagatta, Fabrice Moscheni, Markus Schütz, Frédéric Dufaux
1994 J jnl
J. Vis. Commun. Image Represent.
Frédéric Dufaux, Iole Moccagatta, Fabrice Moscheni, Henri Nicolas
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False