Static extracting method of software intended behavior based on API functions invoking

Guojun Peng, Xuanchen Pan, Jianming Fu, Huanguo Zhang · Wuhan University Journal of Natural Sciences · 2008

The method of extracting and describing the intended behavior of software precisely has become one of the key points in the fields of software behavior’s dynamic and trusted authentication. In this paper, the author proposes a specified measure of extracting SIBDS (software intended behaviors describing sets) statically from the binary executable using the software’s API functions invoking, and also introduces the definition of the structure used to store the SIBDS in detail. Experimental results demonstrate that the extracting method and the storage structure definition offers three strong properties: (i) it can describe the software’s intended behavior accurately; (ii) it demands a small storage expense; (iii) it provides strong capability to defend against mimicry attack.

Read the paper · More papers on PaperTik