Analysis of the Software Behaviour Using Forensic Methods for Computer Security Purposes

Liberios Vokorokos, Branislav Madoš, Marek Čajkovský, Ján Hurtuk, Kristián MORAVČÍK · Acta Electrotechnica et Informatica · 2014

Static analysis of malicious software is a complicated process.This complication stems from the fact that the process of analysis has to be carried out on the malicious binary file which is represented in assembly language and therefore lacks critical semantics such as functions, types and buffers that are only found in the source code of high-level languages.This work presents a method that is built on top of IDA Pro disassembler and can be used for analysis of binary files by describing their structure using finite-state automaton.This kind of approach allows a reverse engineer to perform advanced features such as visualization, comparison, etc on a malicious file.

Read the paper · More papers on PaperTik