Using memory management to detect and extract illegitimate code for malware analysis

Carsten Willems, Felix Freiling, Thorsten Holz · 2012

Exploits that successfully attack computers are typically based on some form of shellcode, i.e., illegitimate code that is injected by the attacker to take control of the system. Detecting and gathering such code is the first step to its detailed analysis. The amount and sophistication of modern malware calls for automated mechanisms that perform such detection and extraction.

Read the paper · More papers on PaperTik