首页> 外文会议>IT in Medicine and Education (ITME), 2011 International Symposium on >The library function recognition algorithm of PE file disassembler research and implementation
【24h】

The library function recognition algorithm of PE file disassembler research and implementation

机译:PE文件反汇编程序的库函数识别算法研究与实现

获取原文

摘要

In order to solve the problem of static library function recognition of Windows PE (Portable Execute) in the field of software reverse engineering, a new extraction algorithm based on the library function signature is presented. The algorithm extracts the library function signature of lib suffix to the files, then the disassembler identifies the functions with the library function signature and return the address and the corresponding library function name in the disassembly phase of PE files. The results show that the recognition algorithm is able to efficiently identify the library function address, and library function blocks.
机译:为了解决软件逆向工程领域Windows PE(Portable Execute)静态库功能识别的问题,提出了一种新的基于库功能签名的提取算法。该算法将lib后缀的库函数签名提取到文件中,然后反汇编程序使用库函数签名识别函数,并在PE文件的反汇编阶段返回地址和相应的库函数名称。结果表明,该识别算法能够有效识别库函数地址和库函数块。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号