Rafal Wcislo

20 papers Misc 2Journal 4Unranked 13
YearRankTypeTitle / Venue / Authors
2020 conf
ICCS (2)
Bartosz Minch, Mateusz Nowak, Rafal Wcislo, Witold Dzwinel
2019 J jnl
CoRR
Witold Dzwinel, Rafal Wcislo, Stan Matwin
2018 conf
ACRI
Marta Panuszewska, Bartosz Minch, Rafal Wcislo, Witold Dzwinel
2017 conf
PPAM (1)
Witold Dzwinel, Adrian Klusek, Rafal Wcislo, Marta Panuszewska, Pawel Topa
2017 J jnl
J. Comput. Sci.
Witold Dzwinel, Rafal Wcislo, Wojciech W. Czech
2017 conf
IML
Witold Dzwinel, Rafal Wcislo, Magdalena Strzoda
2017 conf
MLDM
Witold Dzwinel, Rafal Wcislo
2016 J jnl
ACM Trans. Model. Comput. Simul.
Witold Dzwinel, Rafal Wcislo, David A. Yuen, Shea Miller
2015 Misc conf
ICCS
Witold Dzwinel, Rafal Wcislo
2012 conf
ACRI
Rafal Wcislo, Witold Dzwinel
2012 J jnl
Comput. Sci.
Marcin Worecki, Rafal Wcislo
2011 conf
BIOINFORMATICS
Rafal Wcislo
2011 conf
HEALTHINF
Rafal Wcislo, Jacek Kitowski, Michal Wrzeszcz, Janusz Otfinowski, Karolina Probosz, Artur Sobczyk, Malgorzata Pisula
2010 conf
SummerSim
Rafal Wcislo, Pawel Gosztyla, Witold Dzwinel
2009 ch.
Annual Review of Cybertherapy and Telemedicine
Karolina Probosz, Rafal Wcislo, Janusz Otfinowski, Renata Slota, Jacek Kitowski, Malgorzata Pisula, Artur Sobczyk
2009 conf
PPAM (1)
Rafal Wcislo, Witold Dzwinel
2008 conf
ICCS (2)
Rafal Wcislo, Witold Dzwinel
2004 Misc conf
ICCVG
Rafal Wcislo, Rafal Bigaj
1996 conf
PARA
Rafal Wcislo, Jacek Kitowski, Jacek Moscinski
1995 conf
PARA
Rafal Wcislo, Jacek Kitowski, Jacek Moscinski
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False