ANALYSIS OF DECOMPILED PROGRAM CODE USING ABSTRACT SYNTAX TREES

Nikita A. Gribkov, T. D. Ovasapyan, D. A. Moskvin · Automatic Control and Computer Sciences · 2023

Abstract This article proposes a method for preprocessing fragments of binary program codes for subsequent detection of their similarity using machine learning methods. The method is based on the analysis of pseudocode obtained as a result of decompiling fragments of binary codes. The analysis is performed using attributed abstract syntax trees (AASTs). As part of the study, testing and comparative analysis of the effectiveness of the developed method are carried out. This method makes it possible to increase the efficiency of detecting functionally similar fragments of program code, compared to analogs, by using the semantic context of vertices in abstract syntax trees.

Read the paper · More papers on PaperTik