We present an empirical evaluation of the Tigress obfuscator, focusing on its ability to degrade the precision of static analyses performed by two state-of-the-art tools: mopsa, a source-level static analyzer, and BinaryNinja a binary-level decompiler and analysis platform. By applying a variety of lightweight yet diverse obfuscation strategies-such as control flow flattening, opaque predicates, and data encoding-we systematically assess how these transformations affect the analyzability of C programs. Our findings highlight the scenarios in which obfuscation successfully confuses analysis tools and those where it fails to do so.

Assessing the Effectiveness of the Tigress Obfuscator Against MOPSA and BinaryNinja

Altamura, Nicolò;Bragastini, Enrico;Campion, Marco;Dalla Preda, Mila
2025-01-01

Abstract

We present an empirical evaluation of the Tigress obfuscator, focusing on its ability to degrade the precision of static analyses performed by two state-of-the-art tools: mopsa, a source-level static analyzer, and BinaryNinja a binary-level decompiler and analysis platform. By applying a variety of lightweight yet diverse obfuscation strategies-such as control flow flattening, opaque predicates, and data encoding-we systematically assess how these transformations affect the analyzability of C programs. Our findings highlight the scenarios in which obfuscation successfully confuses analysis tools and those where it fails to do so.
2025
Software Protection
Static Analysis
Code Obfuscation
File in questo prodotto:
File Dimensione Formato  
2025-Checkmate.pdf

accesso aperto

Tipologia: Documento in Pre-print
Licenza: Dominio pubblico
Dimensione 583.49 kB
Formato Adobe PDF
583.49 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11562/1189288
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? 0
social impact