ISCAS OpenIR  > 信息安全国家重点实验室
reconstructing a packed dll binary for static analysis
Wang Xianggen; Feng Dengguo; Su Purui
2009
会议名称5th International Conference on Information Security Practice and Experience, ISPEC 2009
会议录名称Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
会议日期April 13,
会议地点Xian, China
出版地Germany
ISSN3029743
ISBN3642008429
部门归属(1) University of Science and Technology of China; (2) State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences
摘要DLLs (Dynamic Link Libraries) are usually protected by various anti-reversing engineering techniques. One technique commonly used is code packing as packed DLLs hinder static code analysis such as disassembly. In this paper, we propose a technique to reconstruct a binary file for static analysis by loading a DLL and triggering and monitoring the execution of the entry-point function and exported functions of packed DLLs. By monitoring all memory operations and control transfer instructions, our approach extracts the original hidden code which is written into the memory at run-time and constructs a binary based on the original DLL, the codes extracted and the records of control transfers. To demonstrate its effectiveness, we implemented our prototype ReconPD based on QEMU. The experiments show that ReconPD is able to analyze the packed DLLs, yet practical in terms of performance. Moreover, the reconstructed binary files can be successfully analyzed by static analysis tools, such as IDA Pro. © 2009 Springer Berlin Heidelberg.
关键词Computer Crime Embedded Systems Security Of Data Security Systems Static Analysis
主办者Xidian University
内容类型会议论文
URI标识http://ir.iscas.ac.cn/handle/311060/8538
专题信息安全国家重点实验室
推荐引用方式
GB/T 7714
Wang Xianggen,Feng Dengguo,Su Purui. reconstructing a packed dll binary for static analysis[C]. Germany,2009.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Wang Xianggen]的文章
[Feng Dengguo]的文章
[Su Purui]的文章
百度学术
百度学术中相似的文章
[Wang Xianggen]的文章
[Feng Dengguo]的文章
[Su Purui]的文章
必应学术
必应学术中相似的文章
[Wang Xianggen]的文章
[Feng Dengguo]的文章
[Su Purui]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。