BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel

المؤلفون المشاركون

Zhuang, Yi
Pan, Jiaye
Sun, Binglin

المصدر

Security and Communication Networks

العدد

المجلد 2020، العدد 2020 (31 ديسمبر/كانون الأول 2020)، ص ص. 1-19، 19ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2020-01-16

دولة النشر

مصر

عدد الصفحات

19

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

To protect core functions, applications often utilize the countermeasure techniques such as antidebugging to avoid analysis by outsiders, especially the malware.

Dynamic binary instrumentation is commonly used in the analysis of binary programs.

However, it can be easily detected and has stability and applicability problems as it involves program rewriting and just-in-time compilation.

This paper proposes a new lightweight analysis method for binary programs with the assistance of hardware features and the operating system kernel, named BAHK, which can automatically analyze the target program by stealth and has wide applicability.

With the support of underlying infrastructures, this paper designs several optimization strategies and specific analysis approaches at instruction level to reduce the impact of fine-grained analysis on the performance of target program so that it can be well applied in practice.

The experimental results show that the proposed method has good stealthiness, low memory consumption, and positive user experience.

In some cases, it shows better analysis performance than the traditional dynamic binary instrumentation method.

Finally, the real case studies further show its feasibility and effectiveness.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Pan, Jiaye& Zhuang, Yi& Sun, Binglin. 2020. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks،Vol. 2020, no. 2020, pp.1-19.
https://search.emarefa.net/detail/BIM-1208572

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Pan, Jiaye…[et al.]. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks No. 2020 (2020), pp.1-19.
https://search.emarefa.net/detail/BIM-1208572

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Pan, Jiaye& Zhuang, Yi& Sun, Binglin. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks. 2020. Vol. 2020, no. 2020, pp.1-19.
https://search.emarefa.net/detail/BIM-1208572

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1208572