<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">mais</journal-id><journal-title-group><journal-title xml:lang="ru">Моделирование и анализ информационных систем</journal-title><trans-title-group xml:lang="en"><trans-title>Modeling and Analysis of Information Systems</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1818-1015</issn><issn pub-type="epub">2313-5417</issn><publisher><publisher-name>Yaroslavl State University</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.18255/1818-1015-2023-2-140-159</article-id><article-id custom-type="edn" pub-id-type="custom">KBZXLJ</article-id><article-id custom-type="elpub" pub-id-type="custom">mais-1776</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>Algorithms</subject></subj-group></article-categories><title-group><article-title>Об упрощении выражений со смешанной битовой и целочисленной арифметикой</article-title><trans-title-group xml:lang="en"><trans-title>On Simplifying Expressions with Mixed Boolean-Arithmetic</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-1491-524X</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Косолапов</surname><given-names>Юрий Владимирович</given-names></name><name name-style="western" xml:lang="en"><surname>Kosolapov</surname><given-names>Yury V.</given-names></name></name-alternatives><email xlink:type="simple">itaim@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Южный федеральный университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Southern Federal University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2023</year></pub-date><pub-date pub-type="epub"><day>14</day><month>06</month><year>2023</year></pub-date><volume>30</volume><issue>2</issue><fpage>140</fpage><lpage>159</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Косолапов Ю.В., 2023</copyright-statement><copyright-year>2023</copyright-year><copyright-holder xml:lang="ru">Косолапов Ю.В.</copyright-holder><copyright-holder xml:lang="en">Kosolapov Y.V.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://www.mais-journal.ru/jour/article/view/1776">https://www.mais-journal.ru/jour/article/view/1776</self-uri><abstract><p>Выражения со смешанной булевой и целочисленной арифметикой (далее — MBA-выражения, от англ. Mixed Boolean- Arithmetic) от $t$ целочисленных $n$-битных переменных часто находят применение при обфускации (запутывании) программного кода. Запутывание заключается в замене коротких выражений более длинными эквивалентными выражениями, на исследование которых, как представляется, аналитиком может быть затрачено больше времени. В работе показано, что для упрощения линейных MBA-выражений (сокращения количества слагаемых) может быть применена техника, аналогичная технике декодирования линейных кодов по информационным совокупностям. На основе этой техники в работе построены алгоритмы упрощения линейных MBA-выражений: алгоритм нахождения выражения с минимальным числом слагаемых и алгоритм сокращения числа слагаемых. На основе алгоритма сокращения числа слагаемых построен алгоритм, позволяющий оценить стойкость MBA-выражения к упрощению. В работе экспериментально оценена зависимость среднего числа слагаемых в линейном MBA-выражении, возвращаемом алгоритмами упрощения, от разрядности $n$, числа итераций декодирования и мощности набора булевых функций, по которому ищется линейная комбинация с минимальным числом ненулевых коэффициентов. Результаты экспериментов для всех рассмотренных $t$ и $n$ показывают, что если до обфускации линейное MBA-выражение содержало $r=1,2,3$ слагаемых, то разработанные алгоритмы упрощения с вероятностью, близкой к единице, позволяют по обфусцированному варианту этого выражения найти эквивалентное с числом слагаемых не более $r$. В этом заключается главное отличие техники декодирования по информационным совокупностям от известных техник упрощения линейных MBA-выражений, в которых целью является сокращение числа слагаемых до не более чем $2^t$. В работе также установлено, что для случайно сгенерированных линейных MBA-выражений с ростом $n$ среднее число слагаемых в возвращаемом выражении стремится к $2^t$ и не отличается от среднего числа слагаемых в линейном выражении, возвращаемом известными алгоритмами упрощения. Полученные результаты, в частности, позволяют определить $t$ и $n$, для которых количество слагаемых в упрощенном линейном MBA-выражении в среднем будет не менее заданного.</p></abstract><trans-abstract xml:lang="en"><p>Mixed Boolean-Arithmetic expressions (MBA-expressions) with $t$ integer $n$-bit variables are often used for program obfuscations. Obfuscation consists of replacing short expressions with longer equivalent expressions that seem to take the analyst more time to explore. The paper shows that to simplify linear MBA-expressions (reduce the number of terms), a technique similar to the technique of decoding linear codes by information sets can be applied. Based on this technique, algorithms for simplifying linear MBA-expressions are constructed: an algorithm for finding an expression of minimum length and an algorithm for reducing the length of an expression. Based on the length reduction algorithm, an algorithm is constructed that allows to estimate the resistance of an MBA-expression to simplification. We experimentally estimate the dependence of the average number of terms in a linear MBA-expression returned by simplification algorithms on $n$, the number of decoding iterations, and the power of the set of Boolean functions, by which a linear combination with a minimum number of nonzero coefficients is sought. The results of the experiments for all considered $t$ and $n$ show that if before obfuscation the linear MBA-expression contained $r=1,2,3$ terms, then the developed simplification algorithms with a probability close to one allow using the obfuscated version of this expression find an equivalent one with no more than $r$ terms. This is the main difference between the information set decoding technique and the well-known techniques for simplifying linear MBA-expressions, where the goal is to reduce the number of terms to no more than $2^t$. We also found that for randomly generated linear MBA-expressions with increasing $n$, the average number of terms in the returned expression tends to $2^t$ and does not differ from the average number of terms in the linear expression returned by known simplification algorithms. The results obtained, in particular, make it possible to determine $t$ and $n$ for which the number of terms in the simplified linear MBA-expression on average will not be less than the given one.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>обфускация программного кода</kwd><kwd>MBA-выражения</kwd><kwd>упрощение MBA-выражений</kwd><kwd>декодирование по информационным совокупностям</kwd></kwd-group><kwd-group xml:lang="en"><kwd>code obfuscation</kwd><kwd>MBA-expressions</kwd><kwd>simplification of MBA-expressions</kwd><kwd>decoding by information sets</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">B. Barak et al., “On the (im)possibility of obfuscating programs,” in Advances in Cryptology — CRYPTO 2001, 2001, vol. 2139, pp. 1–18.</mixed-citation><mixed-citation xml:lang="en">B. Barak et al., “On the (im)possibility of obfuscating programs,” in Advances in Cryptology — CRYPTO 2001, 2001, vol. 2139, pp. 1–18.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Y. Zhou, A. Main, Y. X. Gu, and H. Johnson, “Information hiding in software with mixed boolean-arithmetic transforms,” in Information Security Applications. WISA 2007, 2007, vol. 4867, pp. 61–75.</mixed-citation><mixed-citation xml:lang="en">Y. Zhou, A. Main, Y. X. Gu, and H. Johnson, “Information hiding in software with mixed boolean-arithmetic transforms,” in Information Security Applications. WISA 2007, 2007, vol. 4867, pp. 61–75.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">S. Gulwani, O. Polozov, and R. Singh, “Program synthesis,” Foundations and Trends in Programming Languages, vol. 4, no. 1-2, pp. 1–119, 2017.</mixed-citation><mixed-citation xml:lang="en">S. Gulwani, O. Polozov, and R. Singh, “Program synthesis,” Foundations and Trends in Programming Languages, vol. 4, no. 1-2, pp. 1–119, 2017.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">B. Reichenwallner and P. Meerwald-Stadler, “Efficient Deobfuscation of Linear Mixed Boolean-Arithmetic Expressions,” in Proceedings of the 2022 ACM Workshop on Research on offensive and defensive techniques in the context of Man At The End (MATE) attacks, 2022, pp. 19–28.</mixed-citation><mixed-citation xml:lang="en">B. Reichenwallner and P. Meerwald-Stadler, “Efficient Deobfuscation of Linear Mixed Boolean-Arithmetic Expressions,” in Proceedings of the 2022 ACM Workshop on Research on offensive and defensive techniques in the context of Man At The End (MATE) attacks, 2022, pp. 19–28.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">L. Zobernig, “Mathematical Aspects of Program Obfuscation,” PhD thesis, The University of Auckland, 2020.</mixed-citation><mixed-citation xml:lang="en">L. Zobernig, “Mathematical Aspects of Program Obfuscation,” PhD thesis, The University of Auckland, 2020.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">P. Garba and M. Favaro, “Saturn-software deobfuscation framework based on LLVM,” in Proceedings of the 3rd ACM Workshop on Software Protection, 2019, pp. 27–38.</mixed-citation><mixed-citation xml:lang="en">P. Garba and M. Favaro, “Saturn-software deobfuscation framework based on LLVM,” in Proceedings of the 3rd ACM Workshop on Software Protection, 2019, pp. 27–38.</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">N. Eyrolles, “Obfuscation with Mixed Boolean-Arithmetic Expressions: reconstruction, analysis and simplification tools,” PhD thesis, Universit'e Paris-Saclay, 2017.</mixed-citation><mixed-citation xml:lang="en">N. Eyrolles, “Obfuscation with Mixed Boolean-Arithmetic Expressions: reconstruction, analysis and simplification tools,” PhD thesis, Universit'e Paris-Saclay, 2017.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">D. Xu et al., “Boosting SMT solver performance on mixed-bitwise-arithmetic expressions,” in Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation, 2021, pp. 651–664.</mixed-citation><mixed-citation xml:lang="en">D. Xu et al., “Boosting SMT solver performance on mixed-bitwise-arithmetic expressions,” in Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation, 2021, pp. 651–664.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">B. Liu, J. Shen, J. Ming, Q. Zheng, J. Li, and D. Xu, “MBA-Blast: Unveiling and Simplifying Mixed Boolean-Arithmetic Obfuscation,” in Proceedings of the 30th USENIX Security Symposium, 2021, pp. 1701–1718.</mixed-citation><mixed-citation xml:lang="en">B. Liu, J. Shen, J. Ming, Q. Zheng, J. Li, and D. Xu, “MBA-Blast: Unveiling and Simplifying Mixed Boolean-Arithmetic Obfuscation,” in Proceedings of the 30th USENIX Security Symposium, 2021, pp. 1701–1718.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">E. Berlekamp, R. McEliece, and H. Van Tilborg, “On the inherent intractability of certain coding problems (corresp.),” IEEE Transactions on Information Theory, vol. 24, no. 3, pp. 384–386, 1978.</mixed-citation><mixed-citation xml:lang="en">E. Berlekamp, R. McEliece, and H. Van Tilborg, “On the inherent intractability of certain coding problems (corresp.),” IEEE Transactions on Information Theory, vol. 24, no. 3, pp. 384–386, 1978.</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">E. Prange, “The use of information sets in decoding cyclic codes,” IRE Transactions on Information Theory, vol. 8, no. 5, pp. 5–9, 1962.</mixed-citation><mixed-citation xml:lang="en">E. Prange, “The use of information sets in decoding cyclic codes,” IRE Transactions on Information Theory, vol. 8, no. 5, pp. 5–9, 1962.</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">C. Peters, “Information-set decoding for linear codes over $mathbbF_q$,” in Post-Quantum Cryptography. PQCrypto 2010, 2010, vol. 6061, pp. 81–94.</mixed-citation><mixed-citation xml:lang="en">C. Peters, “Information-set decoding for linear codes over $mathbbF_q$,” in Post-Quantum Cryptography. PQCrypto 2010, 2010, vol. 6061, pp. 81–94.</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">V. Weger, N. Gassner, and J. Rosenthal, “A survey on code-based cryptography.” 2022.</mixed-citation><mixed-citation xml:lang="en">V. Weger, N. Gassner, and J. Rosenthal, “A survey on code-based cryptography.” 2022.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
