跳到主要导航 跳到搜索 跳到主要内容

Deobfuscation of virtualization-obfuscated code through symbolic execution and compilation optimization

  • Mingyue Liang
  • , Zhoujun Li*
  • , Qiang Zeng
  • , Zhejun Fang
  • *此作品的通讯作者
  • Beihang University
  • Temple University
  • CNCERT/CC

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Virtualization-obfuscation replaces native code in a binary with semantically equivalent and self-defined bytecode, which, upon execution, is interpreted by a custom virtual machine. It makes the code very difficult to analyze and is thus widely used in malware. How to deobfuscate such virtualization obfuscated code has been an important and challenging problem. We approach the problem from an innovative perspective by transforming it into a compilation optimization problem, and propose a novel technique that combines trace analysis, symbolic execution and compilation optimization to defeat virtualization obfuscation. We implement a prototype system and evaluate it against popular virtualization obfuscators; the results demonstrate that our method is effective in deobfuscation of virtualization-obfuscated code.

源语言英语
主期刊名Information and Communications Security - 19th International Conference, ICICS 2017, Proceedings
编辑Sihan Qing, Dongmei Liu, Chris Mitchell, Liqun Chen
出版商Springer Verlag
313-324
页数12
ISBN(印刷版)9783319894997
DOI
出版状态已出版 - 2018
活动19th International Conference on Information and Communications Security, ICICS 2017 - Beijing, 中国
期限: 6 12月 20178 12月 2017

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
10631 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议19th International Conference on Information and Communications Security, ICICS 2017
国家/地区中国
Beijing
时期6/12/178/12/17

指纹

探究 'Deobfuscation of virtualization-obfuscated code through symbolic execution and compilation optimization' 的科研主题。它们共同构成独一无二的指纹。

引用此