首页> 外文会议>ACM SIGSAC Conference on Computer and Communications Security >CoDisasm: Medium Scale Concatic Disassembly of Self-Modifying Binaries with Overlapping Instructions
【24h】

CoDisasm: Medium Scale Concatic Disassembly of Self-Modifying Binaries with Overlapping Instructions

机译:Codisasm:中等规模的自我修改二进制文件的中等规模混合拆卸,具有重叠的指令

获取原文

摘要

Fighting malware involves analyzing large numbers of suspicious binary files. In this context, disassembly is a crucial task in malware analysis and reverse engineering. It involves the recovery of assembly instructions from binary machine code. Correct disassembly of binaries is necessary to produce a higher level representation of the code and thus allow the analysis to develop high-level understanding of its behavior and purpose. Nonetheless, it can be problematic in the case of malicious code, as malware writers often employ techniques to thwart correct disassembly by standard tools. In this paper, we focus on the disassembly of x86 self-modifying binaries with overlapping instructions. Current state-of-the-art disassemblers fail to interpret these two common forms of obfuscation, causing an incorrect disassembly of large parts of the input. We introduce a novel disassembly method, called concatic disassembly, that combines CONCrete path execution with stATIC disassembly. We have developed a standalone disassembler called CoDisasm that implements this approach. Our approach substantially improves the success of disassembly when confronted with both self-modification and code overlap in analyzed binaries. To our knowledge, no other disassembler thwarts both of these obfuscations methods together.
机译:战斗恶意软件涉及分析大量可疑二进制文件。在这种情况下,拆卸是恶意软件分析和逆向工程中的一个重要任务。它涉及从二进制机器代码恢复装配说明。正确的二进制文件的正确拆卸是为了产生更高的代码级别表示,从而允许分析为其行为和目的制定高级了解。尽管如此,在恶意代码的情况下,它可能存在问题,因为恶意软件作家通常采用标准工具挫败正确拆卸的技术。在本文中,我们专注于X86自我修改二进制文件的拆卸,具有重叠的指令。目前最先进的拆卸器无法解释这两个常见的混淆形式,导致输入的大部分拆卸不正确。我们介绍了一种新的拆卸方法,称为混合拆卸,将混凝土路径执行与静态拆卸相结合。我们开发了一个名为CodisaM的独立反汇编,实现了这种方法。我们的方法在分析二进制文件中面对自我修改和代码重叠时,我们的方法大大提高了拆卸的成功。为了我们的知识,没有其他拆解阻碍这两种混淆方法都在一起。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号