Chosen-Instruction Attack Against Commercial Code Virtualization Obfuscators

Chosen-Instruction Attack Against Commercial Code Virtualization Obfuscators
复制标题

DOI:
10.14722/ndss.2022.24015
复制
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Shijia Li;Chunfu Jia;Pengda Qiu;Qiyuan Chen;Jiang Ming;Debin Gao
Shijia Li;Chunfu Jia;Pengda Qiu;Qiyuan Chen;Jiang Ming;Debin Gao
中科院分区:
其他
文献类型:
--
作者:
Shijia Li;Chunfu Jia;Pengda Qiu;Qiyuan Chen;Jiang Ming;Debin Gao

文献摘要

相似文献

-代码虚拟化是一种众所周知的复杂混淆技术,它使用自定义虚拟机(VM)来模拟原始本机指令的语义。商业的基于VM的混淆程序(例如Themida和VMProtect)经常被恶意软件开发人员滥用来隐藏恶意行为。由于商业混淆程序的内部机制是一个黑匣子,因此对于分析师来说,理解虚拟化程序的行为是一个艰巨的挑战。为了弄清楚代码虚拟化机制和设计去模糊技术,分析人员必须对大规模的高度模糊的程序执行逆向工程。这种知识学习过程遭受着痛苦的成本和不精确的痛苦。在这个项目中,我们研究了如何通过一种新的选择指令攻击(CIA)技术从商用的基于VM的混乱器中自动提取知识。我们的想法是受到选择明文攻击的启发,选择明文攻击是一种密码分析攻击模型,目的是获得降低加密方案安全性的信息。给定一个基于VM的商业混淆程序,我们仔细构建输入程序,主动与该混淆程序交互,并从虚拟输出程序中提取知识。我们提出使用锚指令和引导式简化技术分别从输出程序中有效地定位和提取与知识相关的指令。我们的实验结果表明,现代商用的基于VM的混乱器受到了CIA的威胁。我们已经发现了760条锚指令,并从四种最广泛使用的商业混乱器中提取了1915条经过验证的指令映射规则。提取的知识使安全分析人员能够了解虚拟恶意软件并改进去模糊技术。此外,我们还贡献了第一个用于系统评估去模糊技术的细粒度基准测试套件。评估结果表明,三种最先进的去模糊技术不足以对抗现代商业的基于VM的混淆技术,可以通过我们提取的知识来改进
—Code virtualization is a well-known sophisticated obfuscation technique that uses custom virtual machines (VM) to emulate the semantics of original native instructions. Commercial VM-based obfuscators (e.g., Themida and VMProtect) are often abused by malware developers to conceal malicious behaviors. Since the internal mechanism of commercial obfuscators is a black box, it is a daunting challenge for the analyst to understand the behavior of virtualized programs. To figure out the code virtualization mechanism and design deobfuscation techniques, the analyst has to perform reverse-engineering on large-scale highly obfuscated programs. This knowledge learning process suffers from painful cost and imprecision. In this project, we study how to automatically extract knowledge from the commercial VM-based obfuscator via a novel chosen-instruction attack (CIA) technique. Our idea is inspired by chosen-plaintext attack, which is a cryptanalysis attack model to gain information that reduces the security of the encryption scheme. Given a commercial VM-based obfuscator, we carefully construct input programs, proactively interact with the obfuscator, and extract knowledge from virtualized output programs. We propose using the anchor instruction and the guided simplification technique to efficiently locate and extract knowledge-related instructions from output programs, respectively. Our experimental results demonstrate that the modern commercial VM-based obfuscators are under the threat of CIA. We have discovered 760 anchor instructions and extracted 1,915 verified instruction mapping rules from the four most widely used commercial obfuscators. The extracted knowledge enables security analysts to understand virtualized malware and improve deobfuscation techniques. Besides, we also contributed the first fine-grained benchmark suite for systematically evaluating the deobfuscation techniques. The evaluation result shows that three state-of-the-art deobfuscation techniques are insufficient to defeat modern commercial VM-based obfuscators and can be improved by our extracted knowledge