Malware behavior analysis using binary code tracking

Jihun Kim, Jonghee M. Youn · 2017

The rapidly increasing malware goes beyond personal security threats and has a negative effect on criminal society. To prevent these security threats, many anti-virus vendors and analysts are starving to more efficiently distinguish malicious behavior. In order to contribute to this, in this study, we try to detect malicious behavior by tracking the execution flow of binary code. Our method of tracking the execution flow of the binary code utilizing the BFS(Breath-First Search)algorithm advances static analysis based on binary code, but it can be a method combining the advantage of static analysis and the advantage of dynamic analysis. In addition to visualizing malicious behavior as a graph image based on APIs, it is possible to analyze more obviously malicious behavior.

Read the paper · More papers on PaperTik