SREP+SAST: A Comparison of Tools for Reverse Engineering Machine Code to Detect Cybersecurity Vulnerabilities in Binary Executables
Thomas Ryan Devine, Maximillian Campbell, Mallory Anderson, Dale Dzielski · 2022
Cybersecurity of mission components is vital for safety-conscious industries. This paper examines the effectiveness of using existing software reverse engineering products (SREPs) to first reverse engineer binary executables and then detect cybersecurity vulnerabilities through static application security testing (SAST) on the output (SREP+SAST). We analyzed 2.3 million lines of code from test suites and open source software. Results showed that SREP+SAST revealed 48% of the 20,129 vulnerabilities detected by SAST on the source code, including 35% of high-risk vulnerabilities (HRVs). We introduce Smaug, a novel, open source, customized SAST ruleset optimized for HRV detection. Smaug boosted our our best-performing combo by 20% and increased the HRV detection rate to 55%. For further validation, we traced vulnerabilities in source code linked to specific CVEs and found that Smaug improved the detection rate for CVE-specific vulnerabilities by 67% for our best-performing combo. Our methods and code are publicly available and we believe that further improving SREP+SAST could lead to enhanced security for systems that depend on COTS technologies.