K-Hunt++: Improved Dynamic Cryptographic Key Extraction

Thomas Faingnaert, Willem Van Iseghem, Bjorn De Sutter · 2024

We identified several weaknesses in the state-of-the-art cryptographic key extraction algorithm, K-Hunt.It cannot handle code in which key loading and use are spread apart, has problems with modes such as AES CBC that use small data buffers of constant size, and with complex apps in which functionality handles both the key and data.K-Hunt++ overcomes those weaknesses.We demonstrate it on two apps that trigger them and present an ablation study and qualitative analysis of its robustness in the face of obfuscation. CCS Concepts• Security and privacy

Read the paper · More papers on PaperTik