Monirul Sharif1, Andrea Lanzi2, Jonathon Giffin1, Wenke Lee1
1Georgia Institute of Technology 2Universit`a degli Studi di Milano
Monirul Sharif 1 , Andrea Lanzi 2 , Jonathon Giffin 1 , Wenke Lee 1 1 - - PowerPoint PPT Presentation
Monirul Sharif 1 , Andrea Lanzi 2 , Jonathon Giffin 1 , Wenke Lee 1 1 Georgia Institute of Technology 2 Universit`a degli Studi di Milano NDSS 2008 Introduction Introduction We need to understand malware Rootkits Keyloggers Viruses
1Georgia Institute of Technology 2Universit`a degli Studi di Milano
Impeding Malware Analysis Using Conditional Code Obfuscation 2
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 3
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 4
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 5
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 6
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 7
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 8
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 9
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 10
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 11
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 12
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 13
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 14
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 15
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 16
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 17
NDSS 2008
Binary Analysis/ Instrumentation
Malware Source (c/c++) Final obfuscated ELF Binary (x86) ELF Binary (x86) Encrypt marked Blocks with keys remove keys Find candidate conditions conditional code and keys. Perform transformation.
Impeding Malware Analysis Using Conditional Code Obfuscation 18
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 19
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 20
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 21
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 22
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 23
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 24
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 25
NDSS 2008
Impeding Malware Analysis Using Conditional Code Obfuscation 26
NDSS 2008