Obfuscation-Resilient Executable Payload Extraction From Packed Malware

Obfuscation-Resilient Executable Payload Extraction From Packed Malware
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion
Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion
中科院分区:
其他
文献类型:
--
作者:
Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion

文献摘要

相似文献

在过去的二十年里,打包的恶意软件一直是安全分析师面临的一个严峻挑战。不仅确定解包的结束越来越困难,而且高级打包程序还嵌入了各种反分析技巧来阻止逆向工程。由于恶意软件的API提供关于恶意行为的丰富信息,一种常见的反分析策略是API混淆,其从恶意软件的PE标头移除所导入的API的元数据,并且使来自API调用站点的API名称解析复杂化。这样,即使当安全分析人员获得解包的代码时,反汇编程序仍然不能识别导入的API名称,并且解包的代码不能被成功执行。最近,通用二进制解包取得了突破性进展,性能得到了显著改善。然而,重构解包代码的导入表,这是进一步的恶意软件静态/动态分析至关重要的,在很大程度上被忽视了。现有的方法还远未成熟:它们或者可以被各种API混淆方案(例如,被盗代码),或遭受不完全API覆盖。在本文中,我们的目标是实现Windows恶意软件解包的最终目标:从打包和混淆的二进制代码中恢复可执行的恶意软件程序。当原始入口点(OEP)为
Over the past two decades, packed malware is always a ve-ritable challenge to security analysts. Not only is determining the end of the unpacking increasingly difficult, but also advanced packers embed a variety of anti-analysis tricks to impede reverse engineering. As malware’s APIs provide rich information about malicious behavior, one common anti-analysis strategy is API obfuscation, which removes the metadata of imported APIs from malware’s PE header and complicates API name resolution from API callsites. In this way, even when security analysts obtain the unpacked code, a disassem-bler still fails to recognize imported API names, and the unpac-ked code cannot be successfully executed. Recently, generic binary unpacking has made breakthrough progress with noticeable performance improvement. However, reconstructing unpacked code’s import tables, which is vital for further malware static/dynamic analyses, has largely been overlooked. Existing approaches are far from mature: they either can be easily evaded by various API obfuscation schemes (e.g., stolen code), or suffer from incomplete API coverage. In this paper, we aim to achieve the ultimate goal of Windows malware unpacking: recovering an executable malware program from the packed and obfuscated binary code. Based on the process memory when the original entry point (OEP) is