首页> 美国政府科技报告 >Survey of XOR as a Digital Obfuscation Technique in a Corpus of Real Data.
【24h】

Survey of XOR as a Digital Obfuscation Technique in a Corpus of Real Data.

机译:XOR作为实时数据语料库中数字混淆技术的研究综述。

获取原文

摘要

To determine the usage of XOR and the need to adapt additional tools, we analyzed 2,411 drive images from devices acquired around the world for the use of bytewise XOR as an obfuscation technique. Using a modified version of the open source digital forensics tool bulk extractor, evidence of XOR obfuscation was found on 698 drive images, with a maximum of 21,031 XOR- obfuscated features on a single drive. XOR usage in our corpus was observed in files with timestamps between the years 1995 and 2009, but the majority use was found in unallocated space. On the corpus tested, XOR obfuscation was used to circumvent malware detection and reverse engineering, to hide information that was apparently being exfiltrated, and by malware detection tools for their quarantine directory and to distribute malware signatures. We conclude that XOR obfuscation is important to consider when performing malware investigations.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号