Obfuscation-Resilient Executable Payload Extraction From Packed Malware
Obfuscation-Resilient Executable Payload Extraction From Packed Malware
复制标题
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion
中科院分区:
文献类型:
--
作者:
Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion
Over the past two decades, packed malware is always a ve-ritable challenge to security analysts. Not only is determining the end of the unpacking increasingly difficult, but also advanced packers embed a variety of anti-analysis tricks to impede reverse engineering. As malware’s APIs provide rich information about malicious behavior, one common anti-analysis strategy is API obfuscation, which removes the metadata of imported APIs from malware’s PE header and complicates API name resolution from API callsites. In this way, even when security analysts obtain the unpacked code, a disassem-bler still fails to recognize imported API names, and the unpac-ked code cannot be successfully executed. Recently, generic binary unpacking has made breakthrough progress with noticeable performance improvement. However, reconstructing unpacked code’s import tables, which is vital for further malware static/dynamic analyses, has largely been overlooked. Existing approaches are far from mature: they either can be easily evaded by various API obfuscation schemes (e.g., stolen code), or suffer from incomplete API coverage. In this paper, we aim to achieve the ultimate goal of Windows malware unpacking: recovering an executable malware program from the packed and obfuscated binary code. Based on the process memory when the original entry point (OEP) is