Function Grouping & Visualization Through Machine Learning to Aid and Automate Reverse Engineering of Malware

0Citations
Citations of this article
3Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Modern malware analysis is stymied by dependence on the manual components of reverse engineering, which require skilled reverse engineers to perform static analysis. Machine learning and statistical analysis allow for augmentation of static analysis, detection of common benign code in malicious samples, and grouping similar bodies of low-level code. In this work four malware campaigns along with a dataset of known benign executables were utilized to test a process for grouping nearly identical functions to find similarities across executables and identify common code. In addition, those groups were collated to create sets of shared common code which could be used to better understand malware sample variants.

Cite

CITATION STYLE

APA

Cutshaw, M., Foster, R., & Haile, J. (2022). Function Grouping & Visualization Through Machine Learning to Aid and Automate Reverse Engineering of Malware. In 2022 Resilience Week, RWS 2022 - Proceedings. Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/RWS55399.2022.9984035

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free