Cryptographic Function Detection in Obfuscated Binaries via Bit-Precise Symbolic Loop Mapping

Cryptographic Function Detection in Obfuscated Binaries via Bit-Precise Symbolic Loop Mapping
复制标题

DOI:
10.1109/sp.2017.56
复制
发表时间:
2017-05
期刊:
2017 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Dongpeng Xu;Jiang Ming;Dinghao Wu
Dongpeng Xu;Jiang Ming;Dinghao Wu
中科院分区:
其他
文献类型:
--
作者:
Dongpeng Xu;Jiang Ming;Dinghao Wu

文献摘要

被引文献

相似文献

密码功能通常被恶意软件开发人员滥用,以隐藏恶意行为,伪装破坏性有效载荷,并绕过基于网络的防火墙。现在臭名昭著的加密勒索软件甚至加密受害者的计算机文件,直到支付赎金。因此,检测二进制代码中的加密函数是补充现有恶意软件防御和取证的一种有吸引力的方法。然而,无处不在的控制和数据混淆方案使加密函数识别成为一项具有挑战性的工作。现有的检测方法要么对混淆的二进制文件很脆弱,要么是临时的,因为它们只能识别特定的加密函数。在本文中,我们提出了一种新的技术,称为位精确的符号循环映射,以确定加密功能的混淆二进制代码。我们的跟踪为基础的方法捕捉可能的加密算法的语义与位精确的符号执行在一个循环。然后,我们执行引导模糊有效地匹配布尔公式与已知的参考实现。我们已经开发了一个名为CryptoHunt的原型,并使用一组混淆的合成示例,知名的加密库和恶意软件对其进行了评估。与现有的工具相比,CryptoHunt是一种通用的方法,可以在不同的控制和数据混淆方案组合下检测常用的加密函数,如TEA,AES,RC4,MD5和RSA。
Cryptographic functions have been commonly abused by malware developers to hide malicious behaviors, disguise destructive payloads, and bypass network-based firewalls. Now-infamous crypto-ransomware even encrypts victim's computer documents until a ransom is paid. Therefore, detecting cryptographic functions in binary code is an appealing approach to complement existing malware defense and forensics. However, pervasive control and data obfuscation schemes make cryptographic function identification a challenging work. Existing detection methods are either brittle to work on obfuscated binaries or ad hoc in that they can only identify specific cryptographic functions. In this paper, we propose a novel technique called bit-precise symbolic loop mapping to identify cryptographic functions in obfuscated binary code. Our trace-based approach captures the semantics of possible cryptographic algorithms with bit-precise symbolic execution in a loop. Then we perform guided fuzzing to efficiently match boolean formulas with known reference implementations. We have developed a prototype called CryptoHunt and evaluated it with a set of obfuscated synthetic examples, well-known cryptographic libraries, and malware. Compared with the existing tools, CryptoHunt is a general approach to detecting commonly used cryptographic functions such as TEA, AES, RC4, MD5, and RSA under different control and data obfuscation scheme combinations.