Neil Soiffer

25 papers A 4B 1Journal 8Unranked 11
YearRankTypeTitle / Venue / Authors
2024 conf
ICCHP (1)
David Carlisle, Paul Libbrecht, Moritz Schubotz, Neil Soiffer
2024 J jnl
CoRR
David Carliste, Paul Libbrecht, Moritz Schubotz, Neil Soiffer
2020 conf
ICCHP (1)
Neil Soiffer, Jennifer L. Larson
2019 ch.
Web Accessibility (2nd Ed.)
Neil Soiffer, Steve Noble
2018 conf
W4A
Neil Soiffer
2018 conf
ICCHP (1)
Neil Soiffer
2016 conf
ICCHP (1)
Neil Soiffer
2015 conf
W4A
Neil Soiffer
2010 A conf
ASSETS
Preston Lewis, Steve Noble, Neil Soiffer
2009 conf
HCI (7)
Neil Soiffer
2008 J jnl
IEEE Multim.
Dennis Leas, Emilia Persoon, Neil Soiffer, Michael Zacherle
2007 A conf
ASSETS
Neil Soiffer
2005 A conf
ASSETS
Neil Soiffer
1998 J jnl
J. Symb. Comput.
Norbert Kajler, Neil Soiffer
1997 J jnl
SIGSAM Bull.
Neil Soiffer
1995 B conf
ISSAC
Neil Soiffer
1994 J jnl
SIGSAM Bull.
Norbert Kajler, Neil Soiffer
1994 J jnl
ACM SIGCHI Bull.
Norbert Kajler, Neil Soiffer
1992 J jnl
SIGSAM Bull.
S. Kamal Abdali, Guy W. Cherry, Neil Soiffer
1991 conf
C++ Conference
Bruce Cohen, Douglas Hahn, Neil Soiffer
1986 A conf
OOPSLA
S. Kamal Abdali, Guy W. Cherry, Neil Soiffer
1986 conf
SYMSAC
S. Kamal Abdali, Guy W. Cherry, Neil Soiffer
1986 conf
SYMSAC
Carolyn J. Smith, Neil Soiffer
1985 conf
AAECC
William Leler, Neil Soiffer
1985 J jnl
SIGSAM Bull.
William Leler, Neil Soiffer
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False