Static Analysis of Binaries

作者: Silvio Cesare , Yang Xiang , Silvio Cesare , Yang Xiang

DOI: 10.1007/978-1-4471-2909-7_5

关键词:

摘要: Static binary analysis is more difficult than if source code available. In many cases, the analyses are unsound and behaviours omitted to make problems feasible. Heuristics may be required separate data in a disassembly or pointer behaviour weakly modelled statically analysing programs Nevertheless, static of binaries an important area research with number practical applications including detection software theft classification malware. This chapter examines intent that properties features can extracted create useful birthmarks for similarity classification.

参考文章(22)
Michael Van Emmerik, Static Single Assignment for Decompilation ,(2007)
Silvio Cesare, Yang Xiang, Classification of malware using structured control flow AusPDC '10 Proceedings of the Eighth Australasian Symposium on Parallel and Distributed Computing - Volume 107. pp. 61- 70 ,(2010)
Nicholas Nethercote, Julian Seward, Valgrind: A Program Supervision Framework Electronic Notes in Theoretical Computer Science. ,vol. 89, pp. 44- 66 ,(2003) , 10.1016/S1571-0661(04)81042-9
Mila Dalla Preda, Matias Madou, Koen De Bosschere, Roberto Giacobazzi, Opaque predicates detection by abstract interpretation algebraic methodology and software technology. ,vol. 4019, pp. 81- 95 ,(2006) , 10.1007/11784180_9
Fredrik Valeur, Christopher Kruegel, Giovanni Vigna, William Robertson, Static disassembly of obfuscated binaries usenix security symposium. pp. 18- 18 ,(2004)
Johannes Kinder, Florian Zuleger, Helmut Veith, An Abstract Interpretation-Based Framework for Control Flow Reconstruction from Binaries Lecture Notes in Computer Science. pp. 214- 228 ,(2008) , 10.1007/978-3-540-93900-9_19
G. Balakrishnan, T. Reps, D. Melski, T. Teitelbaum, WYSINWYX: What You See Is Not What You eXecute verified software: theories, tools, experiments. pp. 202- 213 ,(2005) , 10.1007/978-3-540-69149-5_22
Silvio Cesare, Yang Xiang, A Fast Flowgraph Based Classification System for Packed and Polymorphic Malware on the Endhost advanced information networking and applications. pp. 721- 728 ,(2010) , 10.1109/AINA.2010.121
Daniel Kästner, Stephan Wilhelm, Generic control flow reconstruction from assembly code Proceedings of the joint conference on Languages, compilers and tools for embedded systems software and compilers for embedded systems - LCTES/SCOPES '02. ,vol. 37, pp. 46- 55 ,(2002) , 10.1145/513829.513839
Balakrishnan Gogul, T Reps, D Melski, T Teitelbaum, WYSINWYX: What you see is not what you eXecute ACM Transactions on Programming Languages and Systems. ,vol. 32, pp. 23- ,(2010) , 10.1145/1749608.1749612