Linear Obfuscation to Combat Symbolic Execution

Linear Obfuscation to Combat Symbolic Execution
复制标题

DOI:
10.1007/978-3-642-23822-2_12
复制
发表时间:
2011-09
期刊:
--
影响因子:
--
通讯作者:
Zhi Wang;Jiang Ming;Chunfu Jia;Debin Gao
Zhi Wang;Jiang Ming;Chunfu Jia;Debin Gao
中科院分区:
其他
文献类型:
--
作者:
Zhi Wang;Jiang Ming;Chunfu Jia;Debin Gao

文献摘要

被引文献

相似文献

基于触发器的代码(在许多情况下是恶意的,但不一定)仅在接收到特定输入时执行。符号执行是发现此类恶意代码和分析触发条件的最有效的技术之一。我们提出了一种新的自动恶意软件混淆技术,使分析基于符号执行困难。与以前提出的技术不同,我们的工具中的混淆代码不使用任何加密操作,只使用线性操作,符号执行被认为是很好的分析。混淆后的代码合并了未解决的问题,并在原始代码中添加了一个简单的循环,使其长度不到100字节,很难与正常程序区分开来。评估表明,应用符号执行混淆代码是低效的,在寻找触发条件。我们讨论了所提出的技术的优点和缺点。
Trigger-based code (malicious in many cases, but not necessarily) only executes when specific inputs are received. Symbolic execution has been one of the most powerful techniques in discovering such malicious code and analyzing the trigger condition. We propose a novel automatic malware obfuscation technique to make analysis based on symbolic execution difficult. Unlike previously proposed techniques, the obfuscated code from our tool does not use any cryptographic operations and makes use of only linear operations which symbolic execution is believed to be good in analyzing. The obfuscated code incorporates unsolved conjectures and adds a simple loop to the original code, making it less than one hundred bytes longer and hard to be differentiated from normal programs. Evaluation shows that applying symbolic execution to the obfuscated code is inefficient in finding the trigger condition. We discuss strengths and weaknesses of the proposed technique.