首页 | 本学科首页   官方微博 | 高级检索  
     

基于动态污点分析的恶意代码通信协议逆向分析方法
引用本文:刘豫,王明华,苏璞睿,冯登国. 基于动态污点分析的恶意代码通信协议逆向分析方法[J]. 电子学报, 2012, 40(4): 661-668. DOI: 10.3969/j.issn.0372-2112.2012.04.007
作者姓名:刘豫  王明华  苏璞睿  冯登国
作者单位:中国科学院软件研究所,信息安全国家重点实验室,北京100190
摘    要: 对恶意代码通信协议的逆向分析是多种网络安全应用的重要基础.针对现有方法在协议语法结构划分的完整性和准确性方面存在不足,对协议字段的语义理解尤为薄弱,提出了一种基于动态污点分析的协议逆向分析方法,通过构建恶意进程指令级和函数级行为的扩展污点传播流图(Extended Taint Propagation Graph, ETPG),完成对协议数据的语法划分和语义理解.通过实现原型系统并使用恶意代码样本进行测试,结果表明本方法可以实现有效的语法和语义分析,具有较高的准确性和可靠性.

关 键 词:恶意代码  协议逆向分析  动态污点分析
收稿时间:2011-02-28

Communication Protocol Reverse Engineering of Malware Using Dynamic Taint Analysis
LIU Yu , WANG Ming-hua , SU Pu-rui , FENG Deng-Guo. Communication Protocol Reverse Engineering of Malware Using Dynamic Taint Analysis[J]. Acta Electronica Sinica, 2012, 40(4): 661-668. DOI: 10.3969/j.issn.0372-2112.2012.04.007
Authors:LIU Yu    WANG Ming-hua    SU Pu-rui    FENG Deng-Guo
Affiliation:(State Key Laboratory of Information Security,Institution of Software,Chinese Academy of Sciences,Beijing 100190,China)
Abstract:Communication protocol reverse engineering of malwares is significant base for various network security applications.However,recent works have limited accuracy and integrity in identifying protocol fields and are especially weak in understanding fields’ semantics.This paper proposed a method for communication protocol reverse engineering based on dynamic taint analysis.By building an extended taint propagation graph(ETPG) recording both instruction and function level behaviors of a malicious process,dividing the protocol data into different syntax fields and inducing the semantic information of individual fields were achieved.A prototype system was implemented and evaluated with malware samples.The results show that this method can divide the syntax fields and extract semantic information accurately and effectively.
Keywords:malware  protocol reverse engineering  dynamic taint analysis
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《电子学报》浏览原始摘要信息
点击此处可从《电子学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号