Software Obfuscation is commonly used by companies to protect their software assets from reverse engineering and code analysis. While many types of obfuscations have been developed and combined, it is not clear how to assess the additional security brought by a particular set of obfuscation transformations. Some approaches rely on code complexity metrics to represent the difficulty in understanding code. Moreover many metrics are computed by tools on source code, which is different from the native code that the attacker will analyse: such metrics might not hold on to the binary code due to the variability introduced by compiler options and optimizations, and the underlying hardware. To this end, we developed GhidraMetricsToolkit, an open-source Ghidra plug-in to compute a collection of complexity metrics on native code. We tested the plug-in on a set of 61 obfuscated binaries generated from two programs using a set of 9 transformations provided by Tigress, each using four different configurations, from which we found that cyclomatic complexity is mostly influenced by EncodeArithmetic, Flatten and EncodeLiterals obfuscations, while entropy is affected by EncodeArithmetic, Inline and Split. These results show how our plug-in can help developers to choose among different obfuscations by assessing the complexity of code.

The Ghidra Metrics Toolkit for obfuscated native code

Gobbo J.;Falcarin P.
2026

Abstract

Software Obfuscation is commonly used by companies to protect their software assets from reverse engineering and code analysis. While many types of obfuscations have been developed and combined, it is not clear how to assess the additional security brought by a particular set of obfuscation transformations. Some approaches rely on code complexity metrics to represent the difficulty in understanding code. Moreover many metrics are computed by tools on source code, which is different from the native code that the attacker will analyse: such metrics might not hold on to the binary code due to the variability introduced by compiler options and optimizations, and the underlying hardware. To this end, we developed GhidraMetricsToolkit, an open-source Ghidra plug-in to compute a collection of complexity metrics on native code. We tested the plug-in on a set of 61 obfuscated binaries generated from two programs using a set of 9 transformations provided by Tigress, each using four different configurations, from which we found that cyclomatic complexity is mostly influenced by EncodeArithmetic, Flatten and EncodeLiterals obfuscations, while entropy is affected by EncodeArithmetic, Inline and Split. These results show how our plug-in can help developers to choose among different obfuscations by assessing the complexity of code.
2026
CEUR Workshop Proceedings
File in questo prodotto:
File Dimensione Formato  
paper58(2).pdf

accesso aperto

Tipologia: Versione dell'editore
Licenza: Accesso libero (no vincoli)
Dimensione 1.34 MB
Formato Adobe PDF
1.34 MB Adobe PDF Visualizza/Apri

I documenti in ARCA sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10278/5126047
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact