• DocumentCode
    2976963
  • Title

    Analysis of Cryptographic Algorithms´ Characters in Binary File

  • Author

    Li Ji-Zhong ; Yin Qing ; Jiang Lie-Hui ; Jia Xin-Hai

  • Author_Institution
    Inf. Sci. & Technol. Inst., Zhengzhou, China
  • fYear
    2012
  • fDate
    14-16 Dec. 2012
  • Firstpage
    219
  • Lastpage
    223
  • Abstract
    Analysis of cryptographic algorithms is becoming more and more important in information security and malware analysis community. In this paper we have studied the static and dynamic characters of cryptography algorithms in program application by reversing a great lot of samples, and have summarized the static characters as crypto constants, lots of bit wise and arithmetic, logical expression, leaf functions and standard library by IDA. For dynamic characters, we have applied pin-tool to extract the characters as dynamic constants, dynamic statistic and memory operation data. Each static and dynamic character also has relevant sample to validate. Lastly, general comparisons have also been taken between these two kind characters and also have brought forward the future work.
  • Keywords
    cryptography; invasive software; IDA; arithmetic expression; binary file; bitwise expression; crypto constants; cryptographic algorithm character analysis; cryptography algorithms; dynamic characters; dynamic statistics; information security community; leaf functions; logical expression; malware analysis community; memory operation data; program application; standard library; static characters; Algorithm design and analysis; Encryption; Entropy; Heuristic algorithms; Libraries; Software algorithms; Crypto Recognition; Cryptographic Algorithms´ Characters; Disassemble; Dynamic Trace; Format Entropy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Computing, Applications and Technologies (PDCAT), 2012 13th International Conference on
  • Conference_Location
    Beijing
  • Print_ISBN
    978-0-7695-4879-1
  • Type

    conf

  • DOI
    10.1109/PDCAT.2012.54
  • Filename
    6589267