Wanmeng Ding

18 papers C 1Journal 5Unranked 12
YearRankTypeTitle / Venue / Authors
2024 conf
ICIC (9)
Li Wen, Pengfei Xue, Yi Shen, Wanmeng Ding, Min Zhang
2023 conf
ICDF2C (1)
Yi Shen, Yuhan Zhang, Yuwei Li, Wanmeng Ding, Miao Hu, Yang Li, Cheng Huang, Jie Wang
2023 J jnl
Reliab. Eng. Syst. Saf.
Wanmeng Ding, Jimeng Li, Weilin Mao, Zong Meng, ZhongJie Shen
2022 conf
AISS
Chengxi Xu, Yunyi Zhang, Fan Shi, Huimin Ma, Wanmeng Ding, Hong Shan
2019 J jnl
Int. J. Digit. Crime Forensics
Hanlin Liu, Jingju Liu, Xuehu Yan, Lintao Liu, Wanmeng Ding, Yue Jiang
2018 J jnl
Symmetry
Wanmeng Ding, Kesheng Liu, Xuehu Yan, Huaixi Wang, Lintao Liu, Qinghong Gong
2018 J jnl
Int. J. Digit. Crime Forensics
Wanmeng Ding, Kesheng Liu, Xuehu Yan, Lintao Liu
2017 conf
ICPCSEE (1)
Wanmeng Ding, Kesheng Liu, Xuehu Yan, Lintao Liu
2017 conf
ICPCSEE (2)
Lintao Liu, Yuliang Lu, Xuehu Yan, Wanmeng Ding
2017 conf
ICCCS (2)
Xuehu Yan, Yuliang Lu, Lintao Liu, Song Wan, Wanmeng Ding, Hanlin Liu
2017 J jnl
Int. J. Digit. Crime Forensics
Xuehu Yan, Yuliang Lu, Lintao Liu, Song Wan, Wanmeng Ding, Hanlin Liu
2017 conf
ICIG (3)
Xuehu Yan, Yuliang Lu, Lintao Liu, Shen Wang, Song Wan, Wanmeng Ding, Hanlin Liu
2017 conf
BigDataSecurity/HPSC/IDS
Wanmeng Ding, Kesheng Liu, Lintao Liu, Xuehu Yan
2017 C conf
PSIVT
Xuehu Yan, Yuliang Lu, Lintao Liu, Song Wan, Wanmeng Ding, Hanlin Liu
2017 conf
ICPCSEE (1)
Xuehu Yan, Yuliang Lu, Lintao Liu, Song Wan, Wanmeng Ding, Hanlin Liu
2016 conf
iThings/GreenCom/CPSCom/SmartData
Xuehu Yan, Yuliang Lu, Lintao Liu, Song Wan, Wanmeng Ding, Hanlin Liu
2016 conf
WICON
Song Wan, Yuliang Lu, Xuehu Yan, Wanmeng Ding, Hanlin Liu
2016 conf
WICON
Xuehu Yan, Yuliang Lu, Lintao Liu, Song Wan, Wanmeng Ding, Hanlin Liu
redb/extractors/decompiler/bninja/analysis/scores.py
← Index redb/extractors/decompiler/bninja/analysis/scores.py python
from collections import deque
from binaryninja import highlevelil
from binaryninja.enums import HighLevelILOperation


class ObfuscationScores:
    def __init__(self, hlil_function):
        self.function = hlil_function
        self._basic_blocks = list(hlil_function.basic_blocks) if hlil_function and hlil_function.basic_blocks else []
        self._block_count = len(self._basic_blocks)

    def flattened_score(self):
        """
        A heuristic for detecting control flow flattening from Tim Blazytko.
        Source: https://www.synthesis.to/2021/03/03/flattening_detection.html
        """
        if self._block_count == 0:
            return 0.0

        max_flattening_ratio = 0.0

        for basic_block in self._basic_blocks:
            dominated = get_dominated_by(basic_block)
            if not any(edge.source in dominated for edge in basic_block.incoming_edges):
                continue
            ratio = len(dominated) / self._block_count
            if ratio > max_flattening_ratio:
                max_flattening_ratio = ratio

        return max_flattening_ratio

    def MBA_score(self):
        """
        Score for MBA is obtained by the number of instructions that have at least one arithmetic operation and
        one logic operation DIVIDED by the number of instructions.
        """
        total = 0
        mba_count = 0

        for ins in self.function.instructions:
            total += 1
            if uses_mba(ins):
                mba_count += 1

        if total == 0:
            return 0.0

        return mba_count / total

def get_dominated_by(dominator):
    """
    Get the dominators that are dominated by the given dominator.
    (To recall the theory, a basic block B is called dominator for A if every path from START
    to A must include B)
    """
    result = set()
    worklist = deque([dominator])

    while worklist:
        block = worklist.popleft()
        if block in result:
            continue
        result.add(block)
        worklist.extend(block.dominator_tree_children)

    return result

_ARITHMETIC_OPS = frozenset({
    HighLevelILOperation.HLIL_ADD,
    HighLevelILOperation.HLIL_NEG,
    HighLevelILOperation.HLIL_SUB,
    HighLevelILOperation.HLIL_MUL,
    HighLevelILOperation.HLIL_DIVS,
    HighLevelILOperation.HLIL_MODS,
})

_LOGIC_OPS = frozenset({
    HighLevelILOperation.HLIL_NOT,
    HighLevelILOperation.HLIL_AND,
    HighLevelILOperation.HLIL_OR,
    HighLevelILOperation.HLIL_XOR,
    HighLevelILOperation.HLIL_LSR,
    HighLevelILOperation.HLIL_LSL,
})

_MBA_OPS = _ARITHMETIC_OPS | _LOGIC_OPS

def uses_mba(hlil_instruction):
    uses_logic = False
    uses_arithmetic = False
    stack = [hlil_instruction]

    while stack:
        instruction = stack.pop()

        if not isinstance(instruction, highlevelil.HighLevelILInstruction):
            continue

        op = instruction.operation

        if op not in _MBA_OPS:
            for operand in instruction.operands:
                if isinstance(operand, highlevelil.HighLevelILInstruction):
                    stack.append(operand)
            continue

        if op in _ARITHMETIC_OPS:
            uses_arithmetic = True
        else:
            uses_logic = True

        if uses_logic and uses_arithmetic:
            return True

        for operand in instruction.operands:
            if isinstance(operand, highlevelil.HighLevelILInstruction):
                stack.append(operand)

    return False