首页> 外文期刊>Procedia Computer Science >Identification of toolchains used to build IoT malware with statically linked libraries
【24h】

Identification of toolchains used to build IoT malware with statically linked libraries

机译:识别用于构建具有静态链接库的IOT恶意软件的工具链

获取原文
获取外文期刊封面目录资料

摘要

Proliferation of IoT devices has caused an increase in malware. Much IoT malware includes static linking of library functions, and their symbols such as function names and addresses are stripped hindering function-level analysis. We previously showed that pattern matching could identify all library functions statically linked to IoT malware for Intel 80386 and all toolchains used to build them, but it remained unclear how our method identified toolchains used to build IoT malware for other architectures. In this paper, we extend our previous method to identify toolchains used to build IoT malware not only for Intel 80386 but for other architectures: ARC, ARM 32-bit, MIPS 32-bit, MIPS 64-bit, mk68k, PowerPC, sh4, SPARC, and x86-64. Evaluation of toolchain identification of 3,991 malware samples showed our method identified all toolchains used to build them. Only 14 toolchains had been used to build the samples, and are all available on the Web. We found 91.4% of samples other than Intel 80386 were built with the toolchain described in the installation guide of Mirai, which was similar to that of Intel 80386. To share the results of this study with the antimalware community, we have published a list of the toolchain names of each sample and the names and addresses of the library functions linked to each sample on GitHub.
机译:物联网设备的扩散导致恶意软件的增加。许多物联网恶意软件包括库函数的静态链接,以及它们的符号,如功能名称和地址是剥离函数级分析。我们之前展示了模式匹配可以识别与英特尔80386的IOT恶意软件静态链接的所有库函数,并且所有用于构建它们的工具链,但它仍然不清楚我们的方法如何确定用于构建其他体系结构的IoT恶意软件的方法。在本文中,我们扩展了先前的方法,以识别用于构建ITEL 80386的IOT恶意软件的工具链,但对于其他架构:弧形,ARM 32位,MIPS 32位,MIPS 64位,MK68K,PowerPC,SH4, SPARC和X86-64。评估工具链识别3,991个恶意软件样本显示我们的方法识别用于构建它们的所有刀鞘。只使用了14个工具箱来构建样本,并且可以在网上获得。我们发现了Intel 80386以外的91.4%的样本是用Mirai的安装指南中描述的工具链构建的,这与英特尔80386类似。要与antimalware社区分享本研究的结果,我们已发布列表每个样本的工具链名称和库函数的名称和地址链接到GitHub上的每个样本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号