DocumentCode
64432
Title
Collaborative reversing of input formats and program data structures for security applications
Author
Zhao Lei ; Ren Xiangyu ; Liu Mengleng ; Wang Lina ; Zhang Hao ; Zhang Huanguo
Author_Institution
Key Lab. of Aerosp. Inf. Security & Trust Comput., Wuhan, China
Volume
11
Issue
9
fYear
2014
fDate
Sept. 2014
Firstpage
135
Lastpage
147
Abstract
Reversing the syntactic format of program inputs and data structures in binaries plays a vital role for understanding program behaviors in many security applications. In this paper, we propose a collaborative reversing technique by capturing the mapping relationship between input fields and program data structures. The key insight behind our paper is that program uses corresponding data structures as references to parse and access different input fields, and every field could be identified by reversing its corresponding data structure. In details, we use a finegrained dynamic taint analysis to monitor the propagation of inputs. By identifying base pointers for each input byte, we could reverse data structures and conversely identify fields based on their referencing data structures. We construct several experiments to evaluate the effectiveness. Experiment results show that our approach could effectively reverse precise input formats, and provide unique benefits to two representative security applications, exploit diagnosis and malware analysis.
Keywords
data structures; groupware; security of data; collaborative reversing technique; exploit diagnosis; input formats; malware analysis; program behavior understanding; program data structures; security applications; Collaboration; Computer security; Data structures; Monitoring; Protocols; Syntactics; fine-grained dynamic tainting; reversing engineering; software security;
fLanguage
English
Journal_Title
Communications, China
Publisher
ieee
ISSN
1673-5447
Type
jour
DOI
10.1109/CC.2014.6969778
Filename
6969778
Link To Document