BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel
Joint Authors
Zhuang, Yi
Pan, Jiaye
Sun, Binglin
Source
Security and Communication Networks
Issue
Vol. 2020, Issue 2020 (31 Dec. 2020), pp.1-19, 19 p.
Publisher
Hindawi Publishing Corporation
Publication Date
2020-01-16
Country of Publication
Egypt
No. of Pages
19
Main Subjects
Information Technology and Computer Science
Abstract EN
To protect core functions, applications often utilize the countermeasure techniques such as antidebugging to avoid analysis by outsiders, especially the malware.
Dynamic binary instrumentation is commonly used in the analysis of binary programs.
However, it can be easily detected and has stability and applicability problems as it involves program rewriting and just-in-time compilation.
This paper proposes a new lightweight analysis method for binary programs with the assistance of hardware features and the operating system kernel, named BAHK, which can automatically analyze the target program by stealth and has wide applicability.
With the support of underlying infrastructures, this paper designs several optimization strategies and specific analysis approaches at instruction level to reduce the impact of fine-grained analysis on the performance of target program so that it can be well applied in practice.
The experimental results show that the proposed method has good stealthiness, low memory consumption, and positive user experience.
In some cases, it shows better analysis performance than the traditional dynamic binary instrumentation method.
Finally, the real case studies further show its feasibility and effectiveness.
American Psychological Association (APA)
Pan, Jiaye& Zhuang, Yi& Sun, Binglin. 2020. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks،Vol. 2020, no. 2020, pp.1-19.
https://search.emarefa.net/detail/BIM-1208572
Modern Language Association (MLA)
Pan, Jiaye…[et al.]. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks No. 2020 (2020), pp.1-19.
https://search.emarefa.net/detail/BIM-1208572
American Medical Association (AMA)
Pan, Jiaye& Zhuang, Yi& Sun, Binglin. BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel. Security and Communication Networks. 2020. Vol. 2020, no. 2020, pp.1-19.
https://search.emarefa.net/detail/BIM-1208572
Data Type
Journal Articles
Language
English
Notes
Includes bibliographical references
Record ID
BIM-1208572