Software Obfuscation is commonly used by companies to protect their software assets from reverse engineering and code analysis. While many types of obfuscations have been developed and combined, it is not clear how to assess the additional security brought by a particular set of obfuscation transformations. Some approaches rely on code complexity metrics to represent the difficulty in understanding code. Moreover many metrics are computed by tools on source code, which is different from the native code that the attacker will analyse: such metrics might not hold on to the binary code due to the variability introduced by compiler options and optimizations, and the underlying hardware. To this end, we developed GhidraMetricsToolkit, an open-source Ghidra plug-in to compute a collection of complexity metrics on native code. We tested the plug-in on a set of 61 obfuscated binaries generated from two programs using a set of 9 transformations provided by Tigress, each using four different configurations, from which we found that cyclomatic complexity is mostly influenced by EncodeArithmetic, Flatten and EncodeLiterals obfuscations, while entropy is affected by EncodeArithmetic, Inline and Split. These results show how our plug-in can help developers to choose among different obfuscations by assessing the complexity of code.
The Ghidra Metrics Toolkit for obfuscated native code
Gobbo J.;Falcarin P.
2026
Abstract
Software Obfuscation is commonly used by companies to protect their software assets from reverse engineering and code analysis. While many types of obfuscations have been developed and combined, it is not clear how to assess the additional security brought by a particular set of obfuscation transformations. Some approaches rely on code complexity metrics to represent the difficulty in understanding code. Moreover many metrics are computed by tools on source code, which is different from the native code that the attacker will analyse: such metrics might not hold on to the binary code due to the variability introduced by compiler options and optimizations, and the underlying hardware. To this end, we developed GhidraMetricsToolkit, an open-source Ghidra plug-in to compute a collection of complexity metrics on native code. We tested the plug-in on a set of 61 obfuscated binaries generated from two programs using a set of 9 transformations provided by Tigress, each using four different configurations, from which we found that cyclomatic complexity is mostly influenced by EncodeArithmetic, Flatten and EncodeLiterals obfuscations, while entropy is affected by EncodeArithmetic, Inline and Split. These results show how our plug-in can help developers to choose among different obfuscations by assessing the complexity of code.| File | Dimensione | Formato | |
|---|---|---|---|
|
paper58(2).pdf
accesso aperto
Tipologia:
Versione dell'editore
Licenza:
Accesso libero (no vincoli)
Dimensione
1.34 MB
Formato
Adobe PDF
|
1.34 MB | Adobe PDF | Visualizza/Apri |
I documenti in ARCA sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



