计算机工程与应用 ›› 2012, Vol. 48 ›› Issue (28): 90-96.

• 研发、设计、测试 • 上一篇    下一篇

一种基于细粒度污点分析的逆向平台

叶永宏,武东英,陈  扬   

  1. 解放军信息工程大学 信息工程学院,郑州 450002
  • 出版日期:2012-10-01 发布日期:2012-09-29

Reverse platform based on fine-grained taint analysis

YE Yonghong, WU Dongying, CHEN Yang   

  1. Institute of Information Engineering, PLA Information Engineering University, Zhengzhou 450002, China
  • Online:2012-10-01 Published:2012-09-29

摘要: 分析对比了现有的行为分析系统的优缺点,针对逆向分析过程中所遇到的代码保护技术等困难,研究并改进了指令级的动态污点分析技术。利用虚拟化技术,设计了一套具有通用性的逆向分析平台。研究插件结构实现可扩展性,以适应漏洞挖掘、恶意行为检测等领域的应用。经实验测试,该设计能与常规的逆向手段配合,显著地提高分析的效率。

关键词: 虚拟化, 污点分析, 逆向分析

Abstract: The advantages and disadvantages of?existing behavioral analysis?system are analysed. To solve the problems encounted in reverse?analysis, such as?code?protection, instruction-level?dynamic?taint?analysis is studied and improved. Based on virtualization technology, a common reverse?analysis?platform is designed?to provide?assistance for?fields such as fuzzing and malicious-code detection. Plug-in?feature is supported to provide extendibility. The experimental?results?prove that ?with conventional?means of?reverse analysis, the proposed method can significantly improve the?analysis?efficiency.

Key words: virtualization, taint?analysis, reverse?analysis