Dynamic Self-modifying Code Detection Based on Backward Analysis

Dynamic Self-modifying Code Detection Based on Backward Analysis
复制标题

基于逆向分析的动态自修改代码检测

DOI:
--
复制
发表时间:
2018
期刊:
International Conference on Computer and Automation Engineering
影响因子:
--
通讯作者:
Zhibin Ye
Zhibin Ye
中科院分区:
--
文献类型:
--
作者:
Dawei Shi;Delong Lv;Zhibin Ye

文献摘要

被引文献

相似文献

自修改代码(SMC)被广泛应用于混淆程序,以提高逆向工程的难度。代码自修改的典型模式是恢复-执行-隐藏,它促使程序在大多数时候隐藏真实的行为,只有在实际运行的情况下才能恢复和执行真实的代码。为了定位SMC并进一步恢复代码的原始逻辑以指导程序分析,提出了一种基于反向分析的动态自修改代码检测方法。我们的方法首先通过动态分析提取执行轨迹,如指令和状态。然后我们维护一个内存集来存储执行指令的内存地址,内存集会在反向搜索轨迹的同时动态更新,同时检查内存写地址是否与当前内存集匹配,以识别“修改然后执行”的模式。通过对上述过程识别出的自修改代码进行验证,可以很容易地对使用自修改代码的程序进行去混淆,实现其原始逻辑。设计并实现了一个可用于自修改代码检测的原型系统。实验结果表明,该方法能有效地跟踪程序的执行,并能减少时间和空间的消耗。
Self-modifying code (SMC) is widely used in obfuscated program for enhancing the difficulty in reverse engineering. The typical mode of self-modifying code is restore-execute-hide, it drives program to conceal real behaviors at most of the time, and only under actual running will the real code be restored and executed. In order to locate the SMC and further recover the original logic of code for guiding program analysis, dynamic self-modifying code detecting method based on backward analysis is proposed. Our method first extracts execution trace such as instructions and status through dynamic analysis. Then we maintain a memory set to store the memory address of execution instructions, the memory set will update dynamically while backward searching the trace, and simultaneously will we check the memory write address to match with current memory set in order to identify the mode "modify then execute". By means of validating self-modifying code which is identified via above procedures, we can easily deobfuscate the program which use self-modifying code and achieve its original logic. A prototype that can be applied in self-modifying code detection is designed and implemented. The evaluation results show our method can trace the execution of program effectively, and can reduce the consumption in time and space.