Kaiyu Hou

16 papers A* 1A 2B 3Journal 5Unranked 5
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Trans. Inf. Forensics Secur.
Qingyang Zeng, Lianjie Wu, Kaiyu Hou, Xue Leng, Yan Chen
2024 A* conf
WWW
Qingyang Zeng, Kaiyu Hou, Xue Leng, Yan Chen
2024 conf
ISC (2)
You Li, Kaiyu Hou, Yunqi He, Yan Chen, Hai Zhou
2023 conf
EuroP4@CoNEXT
Kaiyu Hou, Dhiraj Saharia, Vinod Yegneswaran, Phillip A. Porras
2022 conf
SoCC
Kaiyu Hou, Sen Lin, Yan Chen, Vinod Yegneswaran
2021 A conf
CoNEXT
Kaiyu Hou, Sen Lin, Yan Chen, Vinod Yegneswaran
2021 A conf
MobiSys
Kaiyu Hou, You Li, Yinbo Yu, Yan Chen, Hai Zhou
2020 J jnl
J. Netw. Comput. Appl.
Xiuwen Sun, Hao Li, Dan Zhao, Xingxing Lu, Kaiyu Hou, Chengchen Hu
2020 conf
SIGCOMM Posters and Demos
You Li, Kaiyu Hou, Hai Zhou, Yan Chen
2020 J jnl
IEEE Internet Comput.
Xiaochun Wu, Kaiyu Hou, Xue Leng, Xing Li, Yinbo Yu, Bo Wu, Yan Chen
2019 J jnl
Comput. Networks
Xue Leng, Kaiyu Hou, Yan Chen, Kai Bu, Libin Song, You Li
2019 J jnl
J. Netw. Comput. Appl.
Xiuwen Sun, Hao Li, Dan Zhao, Xingxing Lu, Kaiyu Hou, Chengchen Hu
2019 conf
SIGCOMM Posters and Demos
Yinbo Yu, You Li, Kaiyu Hou, Yan Chen, Hai Zhou, Jianfeng Yang
2018 B conf
IWQoS
Xue Leng, Kaiyu Hou, Yan Chen, Kai Bu, Libin Song
2017 B conf
ICNP
Chengchen Hu, Kaiyu Hou, Hao Li, Ruilong Wang, Peng Zheng, Peng Zhang, Huanzhao Wang
2017 B conf
IWQoS
Xiuwen Sun, Kaiyu Hou, Hao Li, Chengchen Hu
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False