Vasaki Ponnusamy

18 papers B 1Journal 11Unranked 6
YearRankTypeTitle / Venue / Authors
2023 J jnl
IEEE Access
Muhammad Waqas Nadeem, Hock Guan Goh, Yichiet Aun, Vasaki Ponnusamy
2023 J jnl
Syst.
Tze Uei Chai, Hock Guan Goh, Soung-Yue Liew, Vasaki Ponnusamy
2023 J jnl
Comput. Syst. Sci. Eng.
Muhammad Waqas Nadeem, Hock Guan Goh, Yichiet Aun, Vasaki Ponnusamy
2022 J jnl
Int. J. Inf. Sec.
Aun Yichiet, Yen-Min Jasmina Khaw, Ming-Lee Gan, Vasaki Ponnusamy
2022 conf
CITS
Said Bakhshad, Vasaki Ponnusamy, Robithoh Annur, Muhammad Waqas, Hisham Alasmary, Shanshan Tu
2022 J jnl
Comput. Syst. Sci. Eng.
Vasaki Ponnusamy, Mamoona Humayun, N. Z. Jhanjhi, Aun Yichiet, Maram Fahhad Almufareh
2022 J jnl
Comput. Syst. Sci. Eng.
Vasaki Ponnusamy, Aun Yichiet, N. Z. Jhanjhi, Mamoona Humayun, Maram Fahhad Almufareh
2021 J jnl
IEEE Access
Shadab Kalhoro, Mobashar Rehman, Vasaki Ponnusamy, Farhan Bashir Shaikh
2021 J jnl
Intell. Autom. Soft Comput.
Adnan Bin Amanat Ali, Vasaki Ponnusamy, Anbuselvan Sangodiah, Roobaea Alroobaea, N. Z. Jhanjhi, Uttam Ghosh, Mehedi Masud
2020 J jnl
IEEE Access
Sunil Jacob, Mukil Alagirisamy, Varun G. Menon, B. Manoj Kumar, N. Z. Jhanjhi, Vasaki Ponnusamy, Shynu Gopalan Padinjappurathu, Venki Balasubramanian
2020 conf
ACeS
Yichiet Aun, Yen-Min Jasmina Khaw, Ming-Lee Gan, Vasaki Ponnusamy
2019 conf
EBIMCS
Vasaki Ponnusamy, Wong Choon Hong, Aun Yichiet, Robithoh Annur, Ming-Lee Gan
2019 conf
ACeS
Vasaki Ponnusamy, Chan Mee Yee, Adnan Bin Amanat Ali
2014 J jnl
Int. J. Mob. Commun.
Vasaki Ponnusamy, Low Tang Jung, Anang Hudaya Muhamad Amin
2013 conf
ICUIMC
Vasaki Ponnusamy, Mahamat Issa Hassan, Low Tang Jung, Thinaharan Ramachandran
2010 conf
ICITST
Vasaki Ponnusamy, Azween Vitra Abdullah
2010 B conf
Intelligent Environments
Vasaki Ponnusamy, Azween B. Abdullah
2009 J jnl
Int. J. Mob. Commun.
Vasaki Ponnusamy
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False