Главная
Study mode:
on
1
Introduction
2
What is obfuscation
3
Motivation
4
Goal
5
Related Works
6
System Overview
7
Change Analysis
8
ControlDependencies
9
Implicit control dependencies
10
Simplifying transformations
11
Semantic preserving transformations
12
Simplified trace
13
Emulation
14
Examples
15
CFG Comparison
16
Conclusion
Description:
Explore a generic approach to automatic deobfuscation of executable code in this 20-minute IEEE conference talk. Delve into techniques for penetrating and removing obfuscations in malicious software to understand internal logic and develop countermeasures. Learn about semantics-preserving program transformations that simplify obfuscation code without making assumptions about specific obfuscation methods. Discover how this approach has been applied to various obfuscation types, including emulation-based obfuscation with runtime code unpacking and return-oriented programming. Examine the effectiveness of this method in extracting internal logic from code obfuscated using tools like Themida, which previous approaches struggled to handle. Cover topics such as change analysis, control dependencies, simplifying transformations, emulation, and CFG comparison through a comprehensive syllabus.

A Generic Approach to Automatic Deobfuscation of Executable Code

IEEE
Add to list
0:00 / 0:00