Automation and Anti-automation
CSE 598 – Applied Program Analysis and Debugging
Fall 2025
Fish Wang
Arizona State University
Emulators
2
Emulators
3
Symbolic Execution
4
Symbolic Execution (Cont.)
5
Symbolic Constraints
6
mov rax, rbx
cmp rax, 5
je label
label:
!label:
rax == 5
rax != 5
States
7
mov rax, rbx
cmp rax, 5
je label
label:
!label:
rax == 5
rax != 5
Constraint Solver
8
mov rax, rbx
cmp rax, 5
je label
label:
!label:
rax == 5
rax != 5
{x0: 5}
{x0: 8}
Models
Basic blocks
9
mov rax, rbx
cmp rax, 5
je label
label:
!label:
rax == 5
rax != 5
Basic blocks
10
mov rax, rbx
cmp rax, 5
je label
label:
!label:
rax == 5
rax != 5
Say hi to angr
11
Let's solve regme with angr
12
Software Registration Models
13
Software Registration Models
14
Software Registration Models
15
Software Registration Models
16
Securing Registration Models
17
"angrables"
18
Try it
19
Defeating Symbolic Execution
20