BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel

Joint Authors

Zhuang, Yi
Pan, Jiaye
Sun, Binglin

Source

Security and Communication Networks

Issue

Vol. 2020, Issue 2020 (31 Dec. 2020), pp.1-19, 19 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2020-01-16

Country of Publication

Egypt

No. of Pages

19

Main Subjects

Information Technology and Computer Science

Abstract EN

To protect core functions, applications often utilize the countermeasure techniques such as antidebugging to avoid analysis by outsiders, especially the malware.

Dynamic binary instrumentation is commonly used in the analysis of binary programs.

However, it can be easily detected and has stability and applicability problems as it involves program rewriting and just-in-time compilation.

This paper proposes a new lightweight analysis method for binary programs with the assistance of hardware features and the operating system kernel, named BAHK, which can automatically analyze the target program by stealth and has wide applicability.

With the support of underlying infrastructures, this paper designs several optimization strategies and specific analysis approaches at instruction level to reduce the impact of fine-grained analysis on the performance of target program so that it can be well applied in practice.

The experimental results show that the proposed method has good stealthiness, low memory consumption, and positive user experience.

In some cases, it shows better analysis performance than the traditional dynamic binary instrumentation method.

Finally, the real case studies further show its feasibility and effectiveness.

American Psychological Association (APA)

Pan, Jiaye& Zhuang, Yi& Sun, Binglin. 2020. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks،Vol. 2020, no. 2020, pp.1-19.
https://search.emarefa.net/detail/BIM-1208572

Modern Language Association (MLA)

Pan, Jiaye…[et al.]. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks No. 2020 (2020), pp.1-19.
https://search.emarefa.net/detail/BIM-1208572

American Medical Association (AMA)

Pan, Jiaye& Zhuang, Yi& Sun, Binglin. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks. 2020. Vol. 2020, no. 2020, pp.1-19.
https://search.emarefa.net/detail/BIM-1208572

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1208572