Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Efficient Automatic Original Entry Point Detection

Authors
Kim, Gyeong-MinPark, JuhyunJang, Yun-HwanPark, Yongsu
Issue Date
Jul-2019
Publisher
INST INFORMATION SCIENCE
Keywords
anti-reverse engineering; malicious code analysis; code obfuscation; program analysis; computer security
Citation
JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, v.35, no.4, pp.887 - 902
Indexed
SCOPUS
Journal Title
JOURNAL OF INFORMATION SCIENCE AND ENGINEERING
Volume
35
Number
4
Start Page
887
End Page
902
URI
https://scholarworks.bwise.kr/hanyang/handle/2021.sw.hanyang/147473
DOI
10.6688/JISE.201907_35(4).0011
ISSN
1016-2364
Abstract
Malware authors employ sophisticated anti-reverse engineering techniques such as packing, encryption, polymorphism, etc. For a packed file, when launched, the packed executable will reconstruct the code of the original program. The OEP (Original Entry Point) is the address indicating the beginning point of the original code. Previous work or conventional unpacking tools provide a relatively large set of OEP candidates and sometimes OEP is missing among candidates. In this paper, we present an efficient OEP detection scheme for x86 Windows environments. This scheme is designed to find exact one OEP by using three methods. First, we enhanced Isawa et al.'s work by examining branch instructions. Our second method is to track the system parameters relevant to the main function in stack memory to refine OEP candidates. Our third method is that we track the startup function calls to find the installation routine for exception handling. To evaluate feasibility, we implemented our algorithm and then conducted experiments on 16 commercial representative packers and 6 previous unpacking tools/schemes. Experimental results show that even though our scheme produces a single OEP candidate for each packed file, accuracy is the highest (up to 14 times higher than the previous work).
Files in This Item
Go to Link
Appears in
Collections
서울 공과대학 > 서울 컴퓨터소프트웨어학부 > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Park, Yong su photo

Park, Yong su
COLLEGE OF ENGINEERING (SCHOOL OF COMPUTER SCIENCE)
Read more

Altmetrics

Total Views & Downloads

BROWSE