A Study of Advanced Hybrid Execution Using Reverse Traversal
Seongsoo Jang, Hoyeon Kim, Young-Hyun Choi, Tai‐Myoung Chung · 2011
As software analysis techniques have been developed, lots of software analysis tools and anti-malware programs now can easily detect various kinds of malware. However, techniques for avoiding software analysis are also being developed. Polymorphic malware and obfuscated malware use those kinds of techniques, and they cause enormous damage to computer systems all over the world. In this paper, therefore, we suggest advanced hybrid execution using reverse traversal to examine advanced malware. The method we suggest reads in the whole program, creates control flow graph, and traces all the execution paths reversely, so that infeasible paths can also be detected. By traversing the whole execution paths, including infeasible paths, we can sense hidden vulnerabilities. Although we anticipate huge overhead when tracing all the execution paths, multi-core processing is expected to alleviate the overhead.