Proceedings of the Institute for System Programming of the RAS
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Proceedings of ISP RAS:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Proceedings of the Institute for System Programming of the RAS, 2019, Volume 31, Issue 6, Pages 33–64
DOI: https://doi.org/10.15514/ISPRAS-2019-31(6)-3
(Mi tisp469)
 

This article is cited in 2 scientific papers (total in 2 papers)

A software complex for revealing malicious behavior in untrusted binary code

A. B. Bugeryaab, V. Yu. Efimovb, I. I. Kulaginb, V. A. Padaryancb, M. A. Solovevbc, A. Yu. Tikhonovd

a Keldysh Institute of Applied Mathematics of the Russian Academy of Sciences
b Ivannikov Institute for System Programming of the RAS
c Lomonosov Moscow State University
d Bauman Moscow State Technical Univarsity
Full-text PDF (794 kB) Citations (2)
References:
Abstract: One of the main problem of a binary code security analysis is a revealing of malicious behavior in an untrusted program. This task is hard to automate, and it requires a participation of a cybersecurity expert. Existing solutions are aimed on the analyst manual work; automation they provide does not demonstrate a system approach. In case where needed analysis tools are absent, the analyst loses the proper support and he is forced to develop tools on one's own. This greatly slows down him from obtaining the practical results. The paper presents a software complex to solve a revealing of malicious behavior problem as a whole: from creating a controlled execution environment to man guided preparing a high-level description of an analyzed algorithm. A QEMU Developer Toolkit (QDT) is introduced, offering support for the domain specific development life cycle. QDT is especially suited for QEMU virtual machine development, including specialized testing and debugging technologies and tools. A high-level hierarchical flowchart-based representation of a program algorithm is presented, as well as an algorithm for its construction. The proposed representation is based on a hypergraph and it allows both automatic and manual data flow analysis at various detail levels. The developed representation is suitable for automatic analysis algorithms implementation. An approach to improve the quality of the resulting representation of the algorithm is proposed. The approach combines individual data streams into the one that links separate logical modules of the algorithm. A test set based on real programs and model examples has been developed to evaluate the result of constructing the proposed high-level algorithm representation.
Keywords: binary code analysis, flowcharts, data flow analysis, controlled execution, domain specific development environment.
Funding agency Grant number
Russian Foundation for Basic Research 16-29-09632
The work is supported by RFBR grant # 16-29-09632.
Document Type: Article
Language: Russian
Citation: A. B. Bugerya, V. Yu. Efimov, I. I. Kulagin, V. A. Padaryan, M. A. Solovev, A. Yu. Tikhonov, “A software complex for revealing malicious behavior in untrusted binary code”, Proceedings of ISP RAS, 31:6 (2019), 33–64
Citation in format AMSBIB
\Bibitem{BugEfiKul19}
\by A.~B.~Bugerya, V.~Yu.~Efimov, I.~I.~Kulagin, V.~A.~Padaryan, M.~A.~Solovev, A.~Yu.~Tikhonov
\paper A software complex for revealing malicious behavior in untrusted binary code
\jour Proceedings of ISP RAS
\yr 2019
\vol 31
\issue 6
\pages 33--64
\mathnet{http://mi.mathnet.ru/tisp469}
\crossref{https://doi.org/10.15514/ISPRAS-2019-31(6)-3}
Linking options:
  • https://www.mathnet.ru/eng/tisp469
  • https://www.mathnet.ru/eng/tisp/v31/i6/p33
  • This publication is cited in the following 2 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Proceedings of the Institute for System Programming of the RAS
    Statistics & downloads:
    Abstract page:119
    Full-text PDF :137
    References:16
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024