Detecting Cryptography through IR Visualization

Patrick Kochberger, Florian Seitl

2018 International Conference on Software Security and Assurance (ICSSA)(2018)

引用 0|浏览4
暂无评分
摘要
The detection of important functionality in binaries is a complex and time consuming task in reverse engineering and malware analysis. Especially cryptographic routines as part of an executable are of interest to an analyst. There are already several automated techniques for finding cryptography within a binary available, ranging from static signatures detection to dynamic behavioural observation. This paper presents a novel approach for functionality detection through the disassembly of binaries, lifted into an intermediate representation (IR). A visualization of the IR then aids an human analyst to find functionality. We evaluate the approach with a binary containing the libgcrypt cryptographic library. The results suggest this to be another useful method for visual binary analysis.
更多
查看译文
关键词
Cryptography Detection,Visualization,Intermediate Representation,Intermediate Language
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要