Spotting Patterns in C Disassembly
mindtribe.com
mindtribe.com
I believe the term for these patterns is called "lowering."
Edit: Finally found a few references for "lowering" in the context of compilers. Here's a SO reference: http://stackoverflow.com/questions/20252876/wanted-good-defi...
Another interesting topic in this area is calling conventions: the expectations of your compiler/platform on how the stack is arranged, to facilitate "linkage" between callers and callees. The "calling convention" dictates where the return value goes, where the processor registers get saved (so they can be restored when control transfers back from the called function to the caller), and the location of the return address. Also, it varies based on whether you're calling code in your own program or into the operating system -- OS calls always have to scrub all the registers, to avoid leaking protected state back to userspace.
Nice article.
I've found it reasonably interesting to look at at first, but it can get dull relatively quickly, especially when you're first learning.
Most patterns were as easy as tracking down bytecodes.
Reverse engineering was only possible because programs were relatively small. After all, one still had to make up function and argument names.
The code generation portion of the class covers this material from the other end, i.e. at the point where the AST is transformed into assembly code, and it has been super interesting.
This is obvious in retrospect but wasn't to me beforehand: if you're interested in reverse engineering, it's very helpful to study how the assembly was written in the first place.
I enjoyed the part of the course that covered optimization. It was really interesting to get the prof's take on the space.
Anyways, back to the homework :)