Nowadays most of malware samples are packed with runtime packers to complicate the task of reverse engineering and security analysis in order to evade detection of signature-based anti-virus engines. In the overall process of malware analysis, unpacking a packed malicious binary effectively is a necessary preliminary to extract the structure features from the binary for generation of its signature, and therefore several unpacking techniques have been proposed so far that attempt to deal with the packer problem. This brief survey article provides an overview of the currently published prevalent unpacking techniques and tools. It covers the operation process of packing and unpacking, packer detection methods, heuristic policies for spotting original entry point (OEP), environments for runtime unpacking, anti-unpacking techniques, and introduces several typical tools for unpacking.
Datacenter is the important infrastructure to provide resource and service in Internet. Due to the widely observed congestion, all kinds of transmission control mechanisms have been proposed to satisfy diverse network performance demands. Based on InfiniBand (IB) which is widely applied for datacenter construction, this paper proposed a generic testing and evaluation platform IBperf to verify transmission control protocols. We designed a central controller to instruct distributed clients to generate different communication patterns and execute commands of the protocol. The transmission performance can be derived based on the captured packets and digest. In the experiment, IB congestion control (CC) was evaluated through IBperf on our real IB platform. IBperf showed the improvement of fairness and throughput with low overhead based on CC mechanism. It proved IBperf to be an effective tool for the evaluation of IB datacenter.
Abstract. Locating internet instability is very important to diagnose internet problems. The existing methods are under the assumption that instability is triggered by only one event, and these methods are not applicable for the scenario of simultaneous events. This paper presents the first study on characterizing the simultaneous events, finding out where the multiple events happened could be visible and how many events are simultaneously happened. Furthermore, a novel scheme is proposed to accurately pinpoint the origins of instability under simultaneous events by exploring cycles, which is theoretically proved to be feasible.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.