Nader Rafla

24 papers A 3B 1C 1Misc 1Journal 5Unranked 13
YearRankTypeTitle / Venue / Authors
2024 conf
MWSCAS
Alfred Moussa, Nader Rafla
2024 conf
DMIP
Alfred M. Moussa, Richard Groves, Nader Rafla
2023 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Michael R. Wasef, Nader Rafla
2022 J jnl
Microprocess. Microsystems
Luka Daoud, Nader Rafla
2022 conf
SOCC
Luka Daoud, Nader Rafla
2021 conf
MWSCAS
Michael R. Wasef, Nader Rafla
2020 J jnl
CoRR
Luka Daoud, Muhammad Kamran Latif, H. S. Jacinto, Nader Rafla
2020 J jnl
Microprocess. Microsystems
Luka Daoud, Muhammad Kamran Latif, H. S. Jacinto, Nader Rafla
2020 J jnl
Microprocess. Microsystems
Fady Hussein, Luka Daoud, Nader Rafla
2020 B conf
LREC
Eric G. Booth, Jake Carns, Casey Kennington, Nader Rafla
2020 C conf
ISCAS
Michael R. Wasef, Nader Rafla
2019 conf
MWSCAS
Luka Daoud, Nader Rafla
2019 conf
NOCS
Luka Daoud, Nader Rafla
2019 Misc conf
CATA
Luka Daoud, Fady Hussein, Nader Rafla
2019 conf
SoCC
Luka Daoud, Nader Rafla
2018 A conf
FPGA
Fady Hussein, Luka Daoud, Nader Rafla
2018 conf
MWSCAS
Muhammad Kamran Latif, H. S. Jacinto, Luka Daoud, Nader Rafla
2018 conf
MWSCAS
Luka Daoud, Fady Hussein, Nader Rafla
2018 conf
MWSCAS
Luka Daoud, Nader Rafla
2018 A conf
FPGA
Luka Daoud, Muhammad Kamran Latif, Nader Rafla
2017 conf
MWSCAS
H. S. Jacinto, Luka Daoud, Nader Rafla
2016 conf
MWSCAS
Danyal Mohammadi, Luka Daoud, Nader Rafla, Said Ahmed-Zaid
2015 A conf
FPGA
Danyal Mohammadi, Said Ahmed-Zaid, Nader Rafla
2012 conf
MWSCAS
Nader Rafla, Mohamad Sawan, José M. de la Rosa
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False