Loading [MathJax]/jax/output/SVG/config.js
Proceedings of the Institute for System Programming of the RAS
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Proceedings of ISP RAS:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Proceedings of the Institute for System Programming of the RAS, 2016, Volume 28, Issue 5, Pages 93–104
DOI: https://doi.org/10.15514/ISPRAS-2016-28(5)-5
(Mi tisp69)
 

This article is cited in 1 scientific paper (total in 1 paper)

The application of compiler-based obfuscation and diversification for program signature modification

A. R. Nurmukhametov

Institute for System Programming of the Russian Academy of Sciences
Full-text PDF (622 kB) Citations (1)
References:
Abstract: Development of malware detection techniques leads to the evolution of anti-detection techniques. In this paper we discuss possibility of creating an automatic tool for signature modification. In this article we describe our experience in designing and development of such tool. For signature modification in Linux programs we implemented a tool based on LLVM compiler infrastructure and for Windows programs we used post-link instrumentation and optimization tool Syzygy. The former approach requires program source code, while the latter assumes only the presence of debug information. Diversifying and obfuscating transformations were implemented in both cases with the aim of changing the signature of program to prevent matching them the known patterns. Implemented transformations are bogus code insertion, function permutation, instruction substitution, ciphering of constant buffer. As a result we demonstrate proof-of-concept examples which confirm that it is possible to automatically change of program signature for avoiding detection by signature-based analysis. Furthermore we explain drawbacks of this technique and discuss the further ways of development.
Keywords: diversification, obfuscation, signature analysis.
Funding agency Grant number
Russian Foundation for Basic Research 14-01-00462
Bibliographic databases:
Document Type: Article
Language: Russian
Citation: A. R. Nurmukhametov, “The application of compiler-based obfuscation and diversification for program signature modification”, Proceedings of ISP RAS, 28:5 (2016), 93–104
Citation in format AMSBIB
\Bibitem{Nur16}
\by A.~R.~Nurmukhametov
\paper The application of compiler-based obfuscation and diversification for program signature modification
\jour Proceedings of ISP RAS
\yr 2016
\vol 28
\issue 5
\pages 93--104
\mathnet{http://mi.mathnet.ru/tisp69}
\crossref{https://doi.org/10.15514/ISPRAS-2016-28(5)-5}
\elib{https://elibrary.ru/item.asp?id=27679152}
Linking options:
  • https://www.mathnet.ru/eng/tisp69
  • https://www.mathnet.ru/eng/tisp/v28/i5/p93
  • This publication is cited in the following 1 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Proceedings of the Institute for System Programming of the RAS
    Statistics & downloads:
    Abstract page:201
    Full-text PDF :140
    References:45
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2025