Retrofitting Intel CET’s Indirect Branch Tracking into Legacy Binaries through Static Binary Rewriting
Resumo
Modern processors increasingly embed hardware support for control-flow integrity. Intel CET’s Indirect Branch Tracking (IBT) restricts indirect transfers to targets explicitly marked with endbr64. However, legacy binaries that cannot be recompiled remain outside this protection, leaving deployed software exposed to code-reuse attacks. This paper presents BIN2CET, an automated static rewriting system for retrofitting IBT support into legacy ELF binaries without requiring perfect control-flow recovery. The system combines endbr64-based target instrumentation, relocation-aware trampolines to preserve overwritten instructions, and conservative notrack handling for indirect branches that cannot be safely normalized. We evaluate BIN2CET on the 102 CoreUtils programs compiled under multiple optimization levels. The results show complete coverage of recovered function-entry targets in the non-optimized setting and above 80% coverage under optimized layouts. Runtime overhead ranges from approximately 22% to 40%, while attack-surface analysis shows that the policy-valid indirect-control-transfer surface is reduced to less than 1% of the syntactic gadget space. These results indicate that automated static rewriting is a practical path for bringing IBT compatibility to legacy binaries.
Referências
Bernat, A. R. and Miller, B. P. (2011). Anywhere, any-time binary instrumentation. In Proceedings of the 10th ACM SIGPLAN-SIGSOFT Workshop on Program Analysis for Software Tools, Madison.
Botacin, M., da Rocha, V. F., de Geus, P. L., and Grégio, A. (2017). Analysis, anti-analysis, anti-anti-analysis: an overview of the evasive malware scenario. Simpósio Brasileiro de Cibersegurança (SBSeg), pages 250–263.
Botacin, M., Geus, P. L. D., and Grégio, A. (2018). Who watches the watchmen: A security-focused review on current state-of-the-art techniques, tools, and methods for systems and binary analysis on modern platforms. ACM Computing Surveys (CSUR), 51(4):1–34.
Burow, N., Carr, S. A., Nash, J., Larsen, P., Franz, M., Brunthaler, S., and Payer, M. (2017). Control-flow integrity: Precision, security, and performance. ACM Computing Surveys (CSUR), 50(1):1–33.
D’Elia, D. C., Invidia, L., Palmaro, F., and Querzoni, L. (2022). Evaluating dynamic binary instrumentation systems for conspicuous features and artifacts. Digital Threats: Research and Practice, 3(2).
Duck, G. J., Gao, X., and Roychoudhury, A. (2020). Binary rewriting without control flow recovery. In Proceedings of the 41st ACM SIGPLAN International Conference on Programming Language Design and Implementation, Singapore.
Gaidis, A. J., Moreira, J., Sun, K., Milburn, A., Atlidakis, V., and Kemerlis, V. P. (2023). Fineibt: Fine-grain control-flow enforcement with indirect branch tracking. In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses.
Hawkins, W. H., Hiser, J. D., Co, M., Nguyen-Tuong, A., and Davidson, J. W. (2017). Zipr: Efficient static binary rewriting for security. In 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN).
Intel (2019). Control-flow enforcement technology specification. Technical report, Intel. Acesso em: 20 nov. 2024.
Intel (2026). Intel® software development emulator (intel® sde). Accessed: 2026-05-23.
Meng, X. and Liu, W. (2016). Incremental cfg patching for binary rewriting. In IEEE 23rd International Conference on Software Analysis, Evolution, and Reengineering (SANER).
Meng, X. and Miller, B. P. (2016). Binary code is not easy. In Proceedings of the 25th International Symposium on Software Testing and Analysis.
Nance, K. and Eagle, C. (2026). The Ghidra Book, 2nd Edition: The Definitive Guide. No Starch Press.
Nour, B., Pourzandi, M., and Debbabi, M. (2023). A survey on threat hunting in enterprise networks. IEEE Communications Surveys & Tutorials, 25(4):2299–2324.
One, A. (1996). Smashing the stack for fun and profit. Phrack Magazine, 7(49):14–16.
Rice, H. G. (1953). Classes of recursively enumerable sets and their decision problems. Transactions of the American Mathematical Society, 74(1):358–366.
Schulte, E., Brown, M. D., and Folts, V. (2022). A broad comparative evaluation of x86-64 binary rewriters. In Proceedings of the 15th Workshop on Cyber Security Experimentation and Test.
Schwartz, E. J., Avgerinos, T., and Brumley, D. (2011). Q: Exploit hardening made easy. In Proceedings of the 20th USENIX Security Symposium. USENIX Association.
Shacham, H. (2007). The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In Proceedings of the ACM Conference on Computer and Communications Security, pages 552–561.
Shanbhogue, V., Gupta, D., and Sahita, R. (2019). Security analysis of processor instruction set architecture for enforcing control-flow integrity. In Proceedings of the 8th International Workshop on Hardware and Architectural Support for Security and Privacy, New York, NY, USA. ACM.
Smithson, M., Elwazeer, K., Anand, K., Kotha, A., and Barua, R. (2013). Static binary rewriting without supplemental information: Overcoming the tradeoff between coverage and correctness. In 20th Working Conference on Reverse Engineering (WCRE).
Thomas, R. (2017). Lief - library to instrument executable formats. [link].
Xie, M., Wu, C., Zhang, Y., Xu, J., Lai, Y., Kang, Y., Wang, W., and Wang, Z. (2022). Cetis: Retrofitting intel cet for generic and efficient intra-process memory isolation. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, Beijing.
Zhang, M., Qiao, R., Hasabnis, N., and Sekar, R. (2014). A platform for secure static binary instrumentation. In Proceedings of the 10th ACM SIGPLAN/SIGOPS International Conference on Virtual Execution Environments.
Zhang, M. and Sekar, R. (2013). Control flow integrity for cots binaries. In USENIX Security Symposium.
