Generic Detection and Annotations of the Statically Linked Code
Lukáš Ďurfina, Dušan Kolář · Acta Electrotechnica et Informatica · 2013
Detection of the statically linked code is one of the important steps in a process of decompilation.It restricts a code, which can be skipped by the decompiler.Type annotations provide an additional information about the number, types, and suitable names for arguments and return values of recognized functions in recognized statically linked code.This is important for generation of calls for these functions.The detection is based on the generic signatures, which are created from the static libraries.The signatures are composed of the first bytes of library modules, CRC codes, module sizes, public symbols, and optionally tail bits or references.A tree structure of signature improves performance by decreasing a count of compared bytes.Generic approach of detection is achieved by an usage of a common object file format.The process is not restricted on specific architecture or file format.However, there are situations when a conflict in the detection can be resolved only by an analysis in the decompiler.Impact of signature usage is verified by the tests with the decompiler.