[{"data":1,"prerenderedAt":57},["ShallowReactive",2],{"publications-sem86-qrs26":3,"papers-sem86-qrs26-02-related-work":40},{"id":4,"title":5,"authors":6,"awards":7,"bibtex":11,"body":12,"date":27,"description":28,"extension":29,"link":30,"meta":31,"navigation":32,"path":33,"pdf":34,"seo":35,"slug":36,"stem":37,"venue":38,"__hash__":39},"publications\u002Fpublications\u002Fsem86-qrs26.md","Sem86: A Full-System Emulator Without Hard-Coded Semantics","Jos Craaijo, Freek Verbeek, Binoy Ravindran",[8],{"name":9,"url":10},"Best Presentation Award","https:\u002F\u002Fqrs26.techconf.org\u002Ftrack\u002Faward_presentation","",{"type":13,"value":14,"toc":24},"minimark",[15],[16,17,18,19,23],"p",{},"Emulation can be used to run legacy software, analyze malware in a sandboxed environment, or run software compiled for different architectures.\nAn emulator is based on instruction semantics.\nThere is, however, not a single instruction semantics to be followed, as x86 allows undefined behavior.\nIn order to make accurate CPU-specific emulators,\nwe argue the need for an emulator that can easily switch between different semantics.\nHowever, all existing emulators contain hard-coded semantics.\nWe present Sem86, an x86 emulator that loads semantics at runtime from data in an input file.\nWe implement all necessary hardware needed to emulate typical x86 operating systems such as Windows 98, Windows XP and Windows 7.\nAdditionally, we implement a sound card, network card and support for high-resolution display output.\nSem86 can automatically ",[20,21,22],"em",{},"bisect"," instruction execution to determine at which point different semantics would diverge.\nWe demonstrate this by constructing a toy malware example that exploits undefined instruction behavior to detect whether it is running in an emulator,\nand show that Sem86 can pinpoint the exact instruction that is used.",{"title":11,"searchDepth":25,"depth":25,"links":26},2,[],"2026-07-22","Emulation can be used to run legacy software, analyze malware in a sandboxed environment, or run software compiled for different architectures.\nAn emulator is based on instruction semantics.\nThere is, however, not a single instruction semantics to be followed, as x86 allows undefined behavior.\nIn order to make accurate CPU-specific emulators,\nwe argue the need for an emulator that can easily switch between different semantics.\nHowever, all existing emulators contain hard-coded semantics.\nWe present Sem86, an x86 emulator that loads semantics at runtime from data in an input file.\nWe implement all necessary hardware needed to emulate typical x86 operating systems such as Windows 98, Windows XP and Windows 7.\nAdditionally, we implement a sound card, network card and support for high-resolution display output.\nSem86 can automatically bisect instruction execution to determine at which point different semantics would diverge.\nWe demonstrate this by constructing a toy malware example that exploits undefined instruction behavior to detect whether it is running in an emulator,\nand show that Sem86 can pinpoint the exact instruction that is used.","md","https:\u002F\u002Fqrs26.techconf.org\u002F",{},true,"\u002Fpublications\u002Fsem86-qrs26","\u002Ffiles\u002Fsem86.pdf",{"title":5,"description":28},"sem86-qrs26","publications\u002Fsem86-qrs26","QRS'26","2isYelaLp7jOW_ygpxJBHzUdEprIalEWZTRkgsYVd-U",{"id":41,"title":42,"body":43,"date":43,"description":43,"extension":44,"html":45,"meta":46,"navigation":32,"next":47,"path":50,"previous":51,"seo":54,"slug":43,"stem":55,"__hash__":56},"papers\u002Fpublications\u002Fsem86-qrs26\u002F02-related-work.html","Related Work",null,"html","\u003Cstyle>\u002F* Alignment *\u002F\nmtable.right-align mtd,\nmtable mtd.right-align,\nmtable.left-align mtd.right-align,\nmtable.aligned mtd:nth-child(odd) {\n  justify-items: end;\n  text-align: right;\n}\nmtable.cases mtd,\nmtable.left-align mtd,\nmtable mtd.left-align,\nmtable.aligned mtd:nth-child(even),\nmath:is(:not([display])) > mtable.multiline-equation mtd {\n  justify-items: start;\n  text-align: left;\n}\nmtable.cases mtd,\nmtable.aligned mtd,\nmtable mtd.flushed,\nmtable mtd.left-flush {\n  padding-left: 0;\n}\nmtable.cases mtd,\nmtable.aligned mtd,\nmtable mtd.flushed,\nmtable mtd.right-flush {\n  padding-right: 0;\n}\n\n\u002F* Tables *\u002F\nmtable {\n  math-style: inherit;\n}\nmtd {\n  math-depth: auto-add;\n  math-style: compact;\n  math-shift: compact;\n}\n\n\u002F* Equations *\u002F\nmtable.multiline-equation mtd {\n  math-depth: inherit;\n  math-style: inherit;\n  math-shift: inherit;\n  padding: 0;\n}\nmath > mtable.multiline-equation mtr:not(:last-child) mtd {\n  padding-bottom: 0.5em;\n}\n\n\u002F* Fractions *\u002F\nmfrac {\n  padding-inline: 0;\n  margin-inline: 0.1em;\n}\n\n\u002F* Accents *\u002F\nmover[accent=\"true\" i] > :first-child {\n  font-feature-settings: \"dtls\";\n}\nmover.dotted[accent=\"true\" i] > :first-child {\n  font-feature-settings: \"dtls\" 0;\n}\n\n\u002F* Other rules for scriptlevel, displaystyle and math-shift *\u002F\nmunder > :nth-child(2),\nmunderover > :nth-child(2) {\n  math-shift: compact\n}\nmunder[accentunder=\"true\" i] > :not(:first-child),\nmover[accent=\"true\" i] > :not(:first-child) {\n  math-depth: inherit;\n  math-style: inherit;\n  math-shift: inherit;\n}\u003C\u002Fstyle>\u003Cdiv id=\"previous-page\" style=\"display: none\">\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F01-introduction#loc-1\">Introduction\u003C\u002Fa>\u003C\u002Fdiv>\u003Cdiv id=\"next-page\" style=\"display: none\">\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F03-implementation#loc-1\">Implementation\u003C\u002Fa>\u003C\u002Fdiv>\u003Ch2 id=\"loc-1\">2 Related Work\u003C\u002Fh2>\u003Ch3>2.1 System-Level Emulators\u003C\u002Fh3>\u003Cp>There are many x86 emulators. Emulators such as Bochs [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-5\" role=\"doc-biblioref\">7\u003C\u002Fa>] and QEMU [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-4\" role=\"doc-biblioref\">6\u003C\u002Fa>] do not aim to accurately implement undefined behavior, as most software runs correct. Some emulators, such as MartyPC \u003Cspan id=\"loc-2\">[\u003C\u002Fspan>\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-15\" role=\"doc-biblioref\">17\u003C\u002Fa>] implement fully accurate semantics and cycle-accurate timing. However, this work relies on the reverse-engineered 8086\u002F8088 microcode and has currently not advanced beyond the original 808x CPUs. All these emulators hard-code their semantics, meaning the semantics cannot be easily changed, or extracted and translated to different formats.\u003C\u002Fp>\u003Cfigure>\u003Ctable>\u003Cthead>\u003Ctr>\u003Cth>\u003C\u002Fth>\u003Cth>QEMU\u003C\u002Fth>\u003Cth>Bochs\u003C\u002Fth>\u003Cth>x86isa &#x26;\u003Cbr>SAIL\u003C\u002Fth>\u003Cth>Gem5\u003C\u002Fth>\u003Cth>Dasgupta\u003C\u002Fth>\u003Cth>\u003Cspan style=\"font-variant-caps: small-caps\">libLISA\u003C\u002Fspan>\u003C\u002Fth>\u003Cth>\u003Cspan style=\"font-variant-caps: small-caps\">Sem86\u003C\u002Fspan>\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd>Semantics implementation\u003C\u002Ftd>\u003Ctd>Code\u003C\u002Ftd>\u003Ctd>Code\u003C\u002Ftd>\u003Ctd>Data\u003C\u002Ftd>\u003Ctd>Data\u003C\u002Ftd>\u003Ctd>Data\u003C\u002Ftd>\u003Ctd>Data\u003C\u002Ftd>\u003Ctd>Data\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>x86 hardware implemented\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>\u003Cmath>\u003Cmo lspace=\"0em\" rspace=\"0em\">∼\u003C\u002Fmo>\u003C\u002Fmath>\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>System-level emulation\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Execution performance\u003C\u002Ftd>\u003Ctd>++\u003C\u002Ftd>\u003Ctd>+\u003C\u002Ftd>\u003Ctd>--\u003C\u002Ftd>\u003Ctd>-\u003C\u002Ftd>\u003Ctd>--\u003C\u002Ftd>\u003Ctd>+\u003C\u002Ftd>\u003Ctd>+\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Complete system model\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003Ctd>✓\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003Ctd>✗\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cem>\u003Cstrong>Table 1:\u003Cspan style=\"white-space: pre-wrap\"> \u003C\u002Fspan>\u003C\u002Fstrong> Comparison of related work.\u003C\u002Fem>\u003C\u002Fp>\u003C\u002Ffigure>\u003Ch3>2.2 x86 Semantics\u003C\u002Fh3>\u003Cp>Models of x86 semantics, such as the x86isa ACL2 model by Goel et al. [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-9\" role=\"doc-biblioref\">11\u003C\u002Fa>], as well as its translation into SAIL [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-10\" role=\"doc-biblioref\">12\u003C\u002Fa>] and Gem5 [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-6\" role=\"doc-biblioref\">8\u003C\u002Fa>] allow for full-system execution. ACL2 and Gem5 can execute these semantics directly, while SAIL can generate emulators as C or OCaml code.\u003C\u002Fp>\u003Cp>A lack of hardware implementations, as well as performance issues, make it impractical to run real operating systems on these emulators. The emulators do not support most of the hardware required to boot regular operating systems, and are only able to boot Linux kernels. The x86isa project requires compiling Linux from scratch because it does not implement standard x86 timer- and display functionality. Gem5 generally does not execute normal bootloaders, and instead loads a (Linux) kernel image directly. We were unable to verify if the SAIL x86 semantics are able to generate a functional emulator, as only instructions for MIPS emulation are provided.\u003C\u002Fp>\u003Cp>In full-system emulation mode, the ACL2 model can execute around 320 thousand instructions per second [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-9\" role=\"doc-biblioref\">11\u003C\u002Fa>]. The SAIL model has similar execution performance when booting an FreeBSD kernel. At this performance level, it would take two to three hours to boot a typical Windows XP installation, or half a day for Windows 7. This makes it unfeasible to use these emulators for typical x86 operating systems.\u003C\u002Fp>\u003Cp>Pydrofoil \u003Cspan id=\"loc-3\">[\u003C\u002Fspan>\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-16\" role=\"doc-biblioref\">18\u003C\u002Fa>] generates a JITing emulator from the RISC-V SAIL specification and achieves a \u003Cmath>\u003Cmn>250\u003C\u002Fmn>\u003Cmo form=\"infix\" lspace=\"0.2222222222222222em\" rspace=\"0em\">×\u003C\u002Fmo>\u003C\u002Fmath> speedup over the default emulator generated by SAIL. However, despite this speedup, which allows it to reach a peak of 22 million instructions executed per second in some benchmarks, its performance still falls short of QEMU and Bochs: it is still \u003Cmath>\u003Cmn>26.7\u003C\u002Fmn>\u003Cmo form=\"infix\" lspace=\"0.2222222222222222em\" rspace=\"0em\">×\u003C\u002Fmo>\u003C\u002Fmath> slower than QEMU. In comparison, according to our measurements, \u003Cspan style=\"font-variant-caps: small-caps\">Sem86\u003C\u002Fspan> is just 2.1 times slower than QEMU.\u003C\u002Fp>\u003Cp>Captive \u003Cspan id=\"loc-4\">[\u003C\u002Fspan>\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-17\" role=\"doc-biblioref\">19\u003C\u002Fa>] can automatically generate emulators from a specification. In ARM benchmarks, it achieves a \u003Cmath>\u003Cmn>1.68\u003C\u002Fmn>\u003Cmo form=\"infix\" lspace=\"0.2222222222222222em\" rspace=\"0em\">×\u003C\u002Fmo>\u003C\u002Fmath> speedup over QEMU. The emulator runs partially inside a virtual machine, as a bare metal program. A bare metal program can use hardware features typically only accessible by operating systems, which makes it possible to generate more efficient code, but requires a host with virtualization support (KVM). It currently only supports emulation of x86-64 in userspace mode, and does not support 32-bit x86 at all.\u003C\u002Fp>\u003Cp>Many other semantics exist, but only focused on userspace \u003Cspan id=\"loc-5\">[\u003C\u002Fspan>\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-11\" role=\"doc-biblioref\">13\u003C\u002Fa>, \u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-12\" role=\"doc-biblioref\">14\u003C\u002Fa>, \u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-14\" role=\"doc-biblioref\">16\u003C\u002Fa>, \u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-18\" role=\"doc-biblioref\">20\u003C\u002Fa>–\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-20\" role=\"doc-biblioref\">22\u003C\u002Fa>]. For example, Morrisett et al. [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-18\" role=\"doc-biblioref\">20\u003C\u002Fa>] implemented a Coq model for a subset of x86, for use in Google’s Native Client (NaCl). The CompCert compiler [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-19\" role=\"doc-biblioref\">21\u003C\u002Fa>] proves equivalence between C source code and compiled artifacts, using a Coq model for x86 which also only implements a subset of x86. While all of these semantics are executable, and some have been used to implement userspace emulators [\u003Ca href=\"\u002Fpublications\u002Fsem86-qrs26\u002F06-bibliography#loc-14\" role=\"doc-biblioref\">16\u003C\u002Fa>], none are capable of full-system emulation.\u003C\u002Fp>",{},{"url":48,"title":49},"\u002Fpublications\u002Fsem86-qrs26\u002F03-implementation","Implementation","\u002Fpublications\u002Fsem86-qrs26\u002F02-related-work",{"url":52,"title":53},"\u002Fpublications\u002Fsem86-qrs26\u002F01-introduction","Introduction",{"title":42},"publications\u002Fsem86-qrs26\u002F02-related-work","oa7iuV8lkT4pl2CDcJj2eO1Q9WDvjJESTYy9Ef3mP3c",1787086053581]