DocumentCode :
3531681
Title :
Extracting Sent Message Formats from Executables Using Backward Slicing
Author :
Min Liu ; Chunfu Jia ; Lu Liu ; Zhi Wang
Author_Institution :
Coll. of Inf. Tech. Sci., Nankai Univ., Tianjin, China
fYear :
2013
fDate :
9-11 Sept. 2013
Firstpage :
377
Lastpage :
384
Abstract :
Network communication protocol reverse-engineering is important for malicious software analysis. Security analysts need to rewrite messages sent and received by malicious software according to the protocol to control the malware´s malicious behaviors. To enable such rewriting, we need detailed information about the sent message by the malware program in target host in the network dialog. However, recent works on sent message extraction have limitations and the source code of malware program is usually not obtained. This paper proposes an analysis method to extract sent message format by processing executables. This paper obtains the reliable execution trace of malware program firstly, then gets the syntax structure of the send buffer of sent function combining the binary code analysis technique with the binary dynamic backward program slicing technique. Finally we exploit the dynamic taint analysis to extract the semantic information of different syntax fields. The experimental results show that our analysis framework can effectively analyze format information of malware´s sent message.
Keywords :
invasive software; program slicing; reverse engineering; backward slicing; binary code analysis technique; binary dynamic backward program slicing technique; dynamic taint analysis; malicious software analysis; malware program; network communication protocol; reliable execution trace; reverse-engineering; semantic information; sent message extraction; sent message format; source code; syntax structure; Monitoring; Performance analysis; Protocols; Semantics; Silicon; Software; Syntactics; dynamic program slicing; dynamic taint analysis; malicious software; sent message;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Emerging Intelligent Data and Web Technologies (EIDWT), 2013 Fourth International Conference on
Conference_Location :
Xi´an
Print_ISBN :
978-1-4799-2140-9
Type :
conf
DOI :
10.1109/EIDWT.2013.71
Filename :
6631649
Link To Document :
بازگشت