Creative Commons License

Creative Commons Attribution-NonCommercial 4.0 International License
This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License

ORCID

https://orcid.org/0009-0008-9901-7684

Date of Graduation

5-15-2026

Semester of Graduation

Spring

Degree Name

Master of Science (MS)

Department

Department of Computer Science

First Advisor

Xunhua Wang

Second Advisor

Brett C. Tjaden

Third Advisor

Adeen Ayub

Abstract

Real-world binary computer programs are typically generated from corresponding source code (and companion libraries). Source code in a high-level programming language is often much easier to develop than binaries. In information security, however, there are situa- tions where new binaries must be generated directly from existing binaries without the corresponding source code. The mutant and the original binary should ideally be indistin- guishable in terms of binary attribution. In this thesis, we develop an inline binary instrumentation toolkit (IBIT) that can gen- erate binary mutants in an inline manner: the instrumentation code is organically inserted into the existing binary code. The inputs to this tool include an existing binary to be instrumented, a set of instrumentation points specified by memory addresses, and a set of instrumentation code — one for each instrumentation point. IBIT uses existing binary analysis libraries like angr and LIEF. We develop heuristic algorithms for the inline instru- mentation, including complete coverage of machine instructions that need to be updated and computation of update values. IBIT has been tested successfully on several real-world 32-bit and 64-bit Windows binary programs, including the 2013 and 2014 NSA Codebreaker Challenge programs and the DarkSide ransomware.

Available for download on Wednesday, April 12, 2028

Share

COinS