Skip to main content

Machine learning augmented reverse engineering Masters thesis

Machine learning augmented reverse engineering Masters thesis


Malicious software is a burning problem in todays ICT industry. There is an ongoing cat-and-mouse game between malware authors, who are writing more sophisticated code every day and returning to life old malware with new protection methods, and security researchers who are struggling to analyze malicious code and find a way how to stop it. Sophisticated malware has multiple defense layers which serve to fool anti-virus (anti-malware) software, malware analysis platforms, as well as to make it harder for security researchers to analyze malware internal workings. Security researcher has to go through mostly manual process of reverse engineering malware, document malware internal workings, write malware signature (or some other form of malware detection technique) and to see if the damage malware has caused is reversible and how to remove it from the system. By the time that is done malware has already caused often irreversible damage (like a stolen bank account).

Malware, besides the malicious code itself, often contains garbage code, which essentially does nothing and its sole purpose is to confuse security researcher, harmless code, which is not important for understanding malware workings and can be safely skipped over during analysis, as well as various anti-debug and anti-disassembly techniques which are meant to make malware impossible to analyze. Security researcher loses precious time while fighting his way through various anti-debug and anti-disassembly techniques and analyzing code which turns out to have nothing to do with malicious activities. The more time researcher spends analyzing garbage code and defenses, the more damage malware does to users and/or companies. It would be useful to have a system which would help guide researcher while analyzing malware, which could tell him not to waste time on some part of a code because it probably is not important.

As a part of my masters thesis I am going to develop a prototype system which could be used to help shorten the time needed for a researcher to analyze malicious code. Machine learning techniques are going to be used to try to predict if the segment of code is relevant to the current analysis. Researcher leaves plenty of data while doing reverse engineering, and it needs to be seen if that data could be used to teach a classifier whether its okay to skip over CALL or JXX instruction or should researcher analyze that part of the code because it contains important functionality. It should also be investigated if that kind of a system would be able to help researcher to defeat malwares protections.

The idea is to build a system which would be able to learn by watching researcher doing reverse engineering of a malware. System learned in that way would then for each CALL and JXX instruction suggest two options to a researcher:
  • CALL/JXX instruction jumps to the part of a code which is relevant to the analysis and should be investigated,
  • CALL/JXX instruction jumps to the part of a code which is not relevant to the analysis and it can be stepped over.
There are two possibilities if the system is not sure (probability that code segment is either important or it is not important is low) whether the code segment is important for analysis or not. First is that it tells it cannot decide should code segment be analyzed and the second is that it offers no output. The system should learn and improve itself during every reverse engineering session.

The architecture is not yet designed but it is known that the system is going to consist from two components, front-end and back-end.  Front-end is going to be implemented as a plugin to one or more popular debuggers such as ollydbg. Its job description is:
  • record researchers action and program state from which system can make classifications and learn,
  • notify back-end if the classification is wrong (researcher skips over function which is classified important or he analyzes function which is marked non important),
  • display classification result to a researcher.
 During the research phase back-end is going to be separate entity on the same computer, but in the later phase its probably going to be located on a server or part on a server and part on a client computer. Its job description is:
  • conduct learning based on data received from front-end,
  • conduct classification based on data received from front-end.
System needs to be designed to be able to accept ways of different feature extraction simply and it needs to be able to accept multiple classifiers to see which gives the best generalisation capacity with regards to a given problem. It needs to be decided where the program state processing and feature extraction is going to be located with regards to speed and load. I am going to describe each of components in more details as it is developed.

download file now

download
alternative link download

Popular posts from this blog

Mini Militia ReAL DuAL WiELD MOD 3 06 by ARSHAD

Mini Militia ReAL DuAL WiELD MOD 3 06 by ARSHAD Most of my friends and sites visitors request me to create a Dual Wield MOD + Pro pack... I DONE IT......... Features:- � Propack Unlocked � Unlimited Ammo OR Bullets � ReAL DuAL WiELD MOD ( Bugs fixed now its working) � No Reload � One shot Kill ( 4 Bullets per shot ) � Unlimited Boost � Unlimited Bombs � No one can see u in Solo Play Mod Screenshots:- Click below for Download Use Chrome or other default browser for download this mod Dont Use Uc Mini Wait 5 seconds and Skip ad download  file  now

Gta Vice City Ps2 Zip

gta vice city ps2 zip Read and see articles about gta vice city ps2 zip, because you can find the info on this site. in this post there are 8 data picture for gta vice city ps2 zip . for that, if you need more than 8 tips, you have come to the right place. in topic gta vice city ps2 zip we have more data with including how to, tutorial and article up to 3+ info. After you listen and understand what is in the article, you can also download it. so don't worry because your problem will be solved here. Looking 3+ secret info for Gta Vice City Ps Zip and you can enter lots of other information from gta vice city ps2 zip, More than 3+ content that can be obtained like gta vice city san andreas android or list below : hd skins gta vice city • gta vice city san andreas android • grand theft auto vice city stories review playstation • gta place vice city stories psp screenshots • detailed map radar mod gta san andreas •...

Download Sony Vegas Pro 11 Kuyhaa

download sony vegas pro 11 kuyhaa Read and see articles about download sony vegas pro 11 kuyhaa, because you can find the info on this site. in this post there are 8 data picture for download sony vegas pro 11 kuyhaa . for that, if you need more than 8 tips, you have come to the right place. in topic download sony vegas pro 11 kuyhaa we have more data with including how to, tutorial and article up to 4+ info. After you listen and understand what is in the article, you can also download it. so don't worry because your problem will be solved here. Looking 4+ secret info for Sony Vegas Pro Kuyhaa and you can enter lots of other information from download sony vegas pro 11 kuyhaa, More than 4+ content that can be obtained like sony vegas studio hd platinum or list below : sony vegas pro • sony vegas pro beginners tutorial youtube • buy sony vegas studio hd platinum • sony vegas pro crack work bit bit youtube • sony vega...