Abstract
Modern malware analysis is stymied by dependence on the manual components of reverse engineering, which require skilled reverse engineers to perform static analysis. Machine learning and statistical analysis allow for augmentation of static analysis, detection of common benign code in malicious samples, and grouping similar bodies of low-level code. In this work four malware campaigns along with a dataset of known benign executables were utilized to test a process for grouping nearly identical functions to find similarities across executables and identify common code. In addition, those groups were collated to create sets of shared common code which could be used to better understand malware sample variants.
Author supplied keywords
Cite
CITATION STYLE
Cutshaw, M., Foster, R., & Haile, J. (2022). Function Grouping & Visualization Through Machine Learning to Aid and Automate Reverse Engineering of Malware. In 2022 Resilience Week, RWS 2022 - Proceedings. Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/RWS55399.2022.9984035
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.