EnBinDiff: Identifying Data-Only Patches for Binaries
Jian Lin, Dingding Wang, Rui Chang, Lei Wu, Yajin Zhou, Kui Ren · IEEE Transactions on Dependable and Secure Computing · 2021
In this article, we focus ondata-onlypatches, a specific type of security patchesnot incurring any structural changes. As one of the most significant causes leading to false negatives, data-only patches become a fundamental problem that affects all state-of-the-art binary diffing approaches/tools. To this end, we first systematically study data-only patches, and thoroughly illustrate the essence and adverse effect on existing tools. Based on the observations, we further propose and implement a system namedEnBinDiffbased on Value Set Analysis (VSA) to effectively identify data-only patches. Specifically,EnBinDifffirst precisely identifies functions from binaries, and then efficiently locates all “matched” function pairs based on structural binary diffing. After that,EnBinDiffperformsdata-only patch analysis, including stack frame matching and constant value matching, to identify data-only patches from the matched functions. To demonstrate the effectiveness ofEnBinDiff, we conduct an extensive evaluation with multiple datasets. The results demonstrate that the proposed system outperforms state-of-the-art binary diffing tools, and the false negative rate is reduced from 11.02% to 1.63%. Furthermore, we applyEnBinDiffto analyze real-world binaries, and successfully identify 20 1-day vulnerabilities.