Obfuscation resilient search through executable classification

Obfuscation resilient search through executable classification
复制标题

通过可执行分类进行混淆弹性搜索

DOI:
10.1145/3211346.3211352
复制
发表时间:
2018
期刊:
Proceedings of the 2nd ACM SIGPLAN International Workshop on Machine Learning and Programming Languages
影响因子:
--
通讯作者:
Ray, Baishakhi
Ray, Baishakhi
中科院分区:
--
文献类型:
--
作者:
Su, Fang-Hsiang;Bell, Jonathan;Kaiser, Gail;Ray, Baishakhi

文献摘要

参考文献

相似文献

Android应用程序通常在发布前被混淆,这使得分析它们是否存在恶意软件或侵犯知识产权变得困难。模糊器可能通过重命名变量和/或修改程序结构来隐藏代码的真实意图。对于开发人员来说,搜索与混淆的应用程序相关的可执行文件以进行有效的分析是具有挑战性的。以前的模糊弹性搜索方法依赖于应用程序的某些结构部分仍然是里程碑,不受模糊处理的影响。例如,以前的一些方法假设标识符之间的结构关系不会被混淆程序打破;另一些方法假设控制流图保持其结构。这两种方法都很容易被动机模糊的人击败。我们提出了一种新的方法MACNETO,它利用深度学习和指令上的主成分来搜索与混淆的可执行文件相关的程序。MACNETO对模糊器可能执行的修改类型几乎没有做任何假设。我们证明了它对被最先进的改变控制流的混乱器混淆的可执行文件具有很高的搜索精度。此外,我们还展示了MACNETO在帮助开发人员理解可执行文件方面的潜力,在MACNETO中,MACNETO为混淆的可执行文件推断关键字(来自相关的非模糊程序)。
Android applications are usually obfuscated before release, making it difficult to analyze them for malware presence or intellectual property violations. Obfuscators might hide the true intent of code by renaming variables and/or modifying program structures. It is challenging to search for executables relevant to an obfuscated application for developers to analyze efficiently. Prior approaches toward obfuscation resilient search have relied on certain structural parts of apps remaining as landmarks, un-touched by obfuscation. For instance, some prior approaches have assumed that the structural relationships between identifiers are not broken by obfuscators; others have assumed that control flow graphs maintain their structures. Both approaches can be easily defeated by a motivated obfuscator. We present a new approach, MACNETO, to search for programs relevant to obfuscated executables leveraging deep learning and principal components on instructions. MACNETO makes few assumptions about the kinds of modifications that an obfuscator might perform. We show that it has high search precision for executables obfuscated by a state-of-the-art obfuscator that changes control flow. Further, we also demonstrate the potential of MACNETO to help developers understand executables, where MACNETO infers keywords (which are from relevant un-obfuscated programs) for obfuscated executables.
超越复制的代码相似之处
DOI: 10.1109/csmr.2010.33
发表时间: 2010
期刊: 2010 14th European Conference on Software Maintenance and Reengineering
影响因子: --
作者:
Elmar Jürgens;F. Deißenböck;B. Hummel
通讯作者: B. Hummel
DOI: --
发表时间: 2004
期刊: --
影响因子: --
作者:
Haruaki Tamada;Masahide Nakamura;Akito Monden
通讯作者: Haruaki Tamada;Masahide Nakamura;Akito Monden
DOI: --
发表时间: 2016
期刊: IEEE Working Conference on Source Code Analysis and Manipulation
影响因子: --
作者:
Chaiyong Ragkhitwetsagul;J. Krinke;D. Clark
通讯作者: D. Clark
干净的代码:敏捷软件工艺手册
DOI: --
发表时间: 2008
期刊:
影响因子: --
作者:
Robert C. Martin
通讯作者: Robert C. Martin
CCCD:Concolic 代码克隆检测
DOI: 10.1109/wcre.2013.6671332
发表时间: 2013
期刊: 2013 20th Working Conference on Reverse Engineering (WCRE)
影响因子: --
作者:
Daniel E. Krutz;Emad Shihab
通讯作者: Emad Shihab