ISCAS OpenIR  > 信息安全国家重点实验室
reconstructing a packed dll binary for static analysis
Wang Xianggen; Feng Dengguo; Su Purui
2009
Conference Name5th International Conference on Information Security Practice and Experience, ISPEC 2009
SourceLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Conference DateApril 13,
Conference PlaceXian, China
Publish PlaceGermany
ISSN3029743
ISBN3642008429
Department(1) University of Science and Technology of China; (2) State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences
English AbstractDLLs (Dynamic Link Libraries) are usually protected by various anti-reversing engineering techniques. One technique commonly used is code packing as packed DLLs hinder static code analysis such as disassembly. In this paper, we propose a technique to reconstruct a binary file for static analysis by loading a DLL and triggering and monitoring the execution of the entry-point function and exported functions of packed DLLs. By monitoring all memory operations and control transfer instructions, our approach extracts the original hidden code which is written into the memory at run-time and constructs a binary based on the original DLL, the codes extracted and the records of control transfers. To demonstrate its effectiveness, we implemented our prototype ReconPD based on QEMU. The experiments show that ReconPD is able to analyze the packed DLLs, yet practical in terms of performance. Moreover, the reconstructed binary files can be successfully analyzed by static analysis tools, such as IDA Pro. © 2009 Springer Berlin Heidelberg.
KeywordComputer Crime Embedded Systems Security Of Data Security Systems Static Analysis
SponsorshipXidian University
Content Type会议论文
URIhttp://ir.iscas.ac.cn/handle/311060/8538
Collection信息安全国家重点实验室
Recommended Citation
GB/T 7714
Wang Xianggen,Feng Dengguo,Su Purui. reconstructing a packed dll binary for static analysis[C]. Germany,2009.
Files in This Item:
There are no files associated with this item.
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Wang Xianggen]'s Articles
[Feng Dengguo]'s Articles
[Su Purui]'s Articles
Baidu academic
Similar articles in Baidu academic
[Wang Xianggen]'s Articles
[Feng Dengguo]'s Articles
[Su Purui]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Wang Xianggen]'s Articles
[Feng Dengguo]'s Articles
[Su Purui]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.