Catch Me if You Can! Transparent Detection of Shellcode
Damjan Buhov, Richard Thron, Sebastian Schrittwieser · 2016
Shellcodes are malicious code fragments which are usually executed after exploitation of particular vulnerability. Such shellcodes can be packed within a binary in a form of payload and executed on the targeted machine. Detection and analysis of these malicious code fragments is very important, however, it is still a challenging problem due to the use of different evasion techniques. Furthermore, the process of detection and analysis of shellcode usually requires a skilled operator. In this paper, we propose a design and proof-of-concept implementation of a user friendly module for transparent detection of shellcode in Linux binaries. Our proof-of-concept implementation comprises both static and dynamic analysis techniques to successfully detect the presence of such code fragments that could harm the users. We simplified the entire analysis procedure by eliminating the need for a skilled operator and allowing the users to directly interact with our tool. Furthermore, our experimental evaluation proved that our module is able to detect real-world shellcode samples.