Argon: A Toolbase for Evaluating Software Protection Techniques Against Symbolic Execution Attacks

Deepak Adhikari, J. Todd McDonald, Todd R. Andel, J.D. Richardson · SoutheastCon 2022 · 2022

Practical software protection for legitimate programs involves study of a wide variety of different program transformation techniques and the evaluation of those techniques against realistic man-at-the-end (MATE) analysis tools. Currently, state-of-the-art tools used by attackers incorporate automated dynamic symbolic execution (DSE) engines which can considerably reduce analysis time of obfuscated portions of code. Measuring the resilience of proposed protection schemes against such attacks has thus become central in understanding the limits of obfuscation in practice. In this paper we present Argon, a tool that combines the ability to generate, obfuscate and symbolically analyze code. The main goal of this tool is to help researchers easily setup and execute empirical studies on obfuscated program variants and evaluate the resistance to symbolic analysis attacks. Argon is intended to increase research involvement in software protection studies by avoiding the steep learning curve that often accompanies the use of symbolic analysis tools. In addition, Argon can also make research more efficient by allowing users to analyze files in bulk rather than individually, while also supporting report generation to summarize execution results. To demonstrate its effectiveness, we used Argon to analyze over 15,000 C source files on both workstation and super-computing class hardware over the course of two months.

Read the paper · More papers on PaperTik