2011
DOI: 10.1587/transinf.e94.d.1778
|View full text |Cite
|
Sign up to set email alerts
|

An Empirical Evaluation of an Unpacking Method Implemented with Dynamic Binary Instrumentation

Abstract: SUMMARYMany malicious programs we encounter these days are armed with their own custom encoding methods (i.e., they are packed) to deter static binary analysis. Thus, the initial step to deal with unknown (possibly malicious) binary samples obtained from malware collecting systems ordinarily involves the unpacking step. In this paper, we focus on empirical experimental evaluations on a generic unpacking method built on a dynamic binary instrumentation (DBI) framework to figure out the applicability of the DBI-… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2013
2013
2018
2018

Publication Types

Select...
2
1
1

Relationship

1
3

Authors

Journals

citations
Cited by 4 publications
(1 citation statement)
references
References 18 publications
0
1
0
Order By: Relevance
“…Kawakoya et al [10] focus on memory access 'write', 'read', and 'execute' of packed programs to detect the OEP, and Jeong et al [24] focus on entropy scores in each section of a packed program on the memory to do so. Kim et al [11] focus on a write-execute transition to spot more likely OEP candidates. Their system stores every written instruction, and it searches for a sequence of written instructions that have been executed successively.…”
Section: Related Workmentioning
confidence: 99%
“…Kawakoya et al [10] focus on memory access 'write', 'read', and 'execute' of packed programs to detect the OEP, and Jeong et al [24] focus on entropy scores in each section of a packed program on the memory to do so. Kim et al [11] focus on a write-execute transition to spot more likely OEP candidates. Their system stores every written instruction, and it searches for a sequence of written instructions that have been executed successively.…”
Section: Related Workmentioning
confidence: 99%