DocumentCode
525332
Title
ROPTool: A reverse engineering assistant tool for dynamic analysis
Author
Miao, Qi-Guang ; Yang, Yuan-Zhu ; Hui Liu ; Ying Cao ; Yun-Wang, Yun-Wang ; Liu, Zhong-Lin ; Zhang, Xian-Guo
Author_Institution
Sch. of Comput. Sci. & Technol., Xidian Univ., Xi´´an, China
Volume
2
fYear
2010
fDate
25-27 June 2010
Abstract
The aim of reverse engineering (RE) is to draw out many kinds of information from existing software and using this information for system renovation and program understanding. But the potential and limitations of reverse engineering techniques is still a matter of a debate and investigation. Current reverse engineering technique focuses on regaining information by using analysis tools. The main purpose of these tools essentially is to aid maintainers understand the program. The fully automatic tools of software reverse engineering are impossible in general. So the demand for different assistant analysis tools grows significantly, including the static and the dynamic analysis tools. In this paper, a dynamic analysis tool for reverse engineering analysis we developed, named ROPTool, is introduced. The ROPTool makes use of the modified virtual machine QEMU to obtain the important information for people to understand the software, and it overcomes the shortcomings of the traditional dynamic analysis tools.
Keywords
reverse engineering; software tools; system monitoring; virtual machines; ROPTool; analysis tools; dynamic analysis; program understanding; reverse engineering assistant tool; system renovation; virtual machine QEMU; Computer science; Decision making; Information analysis; Reverse engineering; Software engineering; Software systems; Software tools; Systems engineering and theory; Terminology; Virtual machining; Dynamic Analysis; Reverse Engineering; System Call;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Design and Applications (ICCDA), 2010 International Conference on
Conference_Location
Qinhuangdao
Print_ISBN
978-1-4244-7164-5
Electronic_ISBN
978-1-4244-7164-5
Type
conf
DOI
10.1109/ICCDA.2010.5541220
Filename
5541220
Link To Document