White Papers

Impeding Malware Analysis Using Conditional Code Obfuscation

Category: Security

Tags: malware

Overview Malware programs that incorporate trigger-based behavior initiate malicious activities based on conditions satisfied only by specific inputs. State-of-the-art malware analyzers discover code guarded by triggers via multiple path exploration, symbolic execution, or forced conditional execution, all without knowing the trigger inputs. This paper presents a malware obfuscation technique that automatically conceals specific trigger-based behavior from these malware analyzers. Their technique automatically transforms a program by encrypting code that is conditionally dependent on an input value with a key derived from the input and then removing the key from the program. They have implemented a compiler-level tool that takes a malware source program and automatically generates an obfuscated binary.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Georgia Institute of Technology
File Format
PDF
Date Published
Jun 20, 2009
Format
White Papers
Topics
Spyware, Network Security

Similiar White Papers

Social Networking: Brave New World or Revolution from Hell? A look at the phenomenon of Social Networking and the implications for Businesses

Social Networking: Brave New World or Revolution from Hell? A look at the phenomenon of Social Networking and the implications for Businesses

According to recent surveys, employee social networking is growing rapidly, on hot sites such as Facebook, LinkedIn and

Publisher: MessageLabs, now part of Symantec  |  Tags: enterprise security, social networking

Sophos Endpoint Security and Control - Free 30 Day Trial

Sophos Endpoint Security and Control - Free 30 Day Trial

Cross-platform security and control for your desktops, laptops, file servers and mobile devices. Sophos delivers complet

Publisher: Sophos  |  Tags: adware, mobile devices, spyware, voip

Antivirus Software and Disk Defragmentation

Antivirus Software and Disk Defragmentation

Want to speed up your antivirus scans? After years of anecdotal data from Diskeeper customers about the reduction in vir

Publisher: Diskeeper  |  Tags: antivirus, data, software

Sophos Web Security and Control - Free 30 Day Trial

Sophos Web Security and Control - Free 30 Day Trial

Block spyware, viruses, phishing, malware, anonymizing proxies and other unwanted applications at the gateway and enable

Publisher: Sophos  |  Tags: applications, malware, phishing, spyware

TTAnalyze: A Tool for Analyzing Malware

TTAnalyze: A Tool for Analyzing Malware

Malware analysis is the process of determining the purpose and functionality of a given malware sample (such as a virus,

Publisher: IKARUS Security Software  |  Tags: api, malware, virus

Georgia Institute of Technology White Papers

Scalability of Network-Failure Resilience

Scalability of Network-Failure Resilience

This work quantifies scalability of network resilience upon failures. It characterize resilience as the percentage of lo

Publisher: Georgia Institute of Technology  |  Tags: network

Bandwidth Estimation: Metrics, Measurement Techniques, and Tools

Bandwidth Estimation: Metrics, Measurement Techniques, and Tools

In a packet network, the terms "Bandwidth" or "Throughput" often characterize the amount of data that the network can tr

Publisher: Georgia Institute of Technology  |  Tags: data, ip, network, open source, peer-to-peer

Bandwidth Estimation and Robust Video Streaming Over 802.11e Wireless LANs

Bandwidth Estimation and Robust Video Streaming Over 802.11e Wireless LANs

Streaming high quality Audio/Video (AV) from home media sources to TV sets over a Wireless Local Area Network (WLAN) is

Publisher: Georgia Institute of Technology  |  Tags: qos, tv

Improving the Performance of TCP Wireless Video Streaming With a Novel Playback Adaptation Algorithm

Improving the Performance of TCP Wireless Video Streaming With a Novel Playback Adaptation Algorithm

This paper proposes a playback adaptation algorithm for video streaming with TCP in wireless networks where both handoff

Publisher: Georgia Institute of Technology  |  Tags: ip, wireless networks

A Cooperative Intrusion Detection System for Ad Hoc Networks

A Cooperative Intrusion Detection System for Ad Hoc Networks

Mobile Ad hoc NETworking (MANET) has become an exciting and important technology in recent years because of the rapid pr

Publisher: Georgia Institute of Technology  |  Tags: management, network