Proceedings of the 6th Workshop on Software Security, Protection, and Reverse Engineering 2016
DOI: 10.1145/3015135.3015136
|View full text |Cite
|
Sign up to set email alerts
|

Metadata recovery from obfuscated programs using machine learning

Abstract: Obfuscation is a mechanism used to hinder reverse engineering of programs. To cope with the large number of obfuscated programs, especially malware, reverse engineers automate the process of deobfuscation i.e. extracting information from obfuscated programs. Deobfuscation techniques target specific obfuscation transformations, which requires reverse engineers to manually identify the transformations used by a program, in what is known as metadata recovery attack. In this paper, we present Oedipus, a Python fra… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
11
0
1

Year Published

2018
2018
2023
2023

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 10 publications
(12 citation statements)
references
References 13 publications
(16 reference statements)
0
11
0
1
Order By: Relevance
“…One is the traditional k-folds cross-validation with scores in black colored font. e other is made with the functionality-based cross-validation approach in red colored font, used in Salem et al related work [53]. Besides, we use as a traditional single-model random-forest algorithm throughout all our studies.…”
Section: Preliminary Studiesmentioning
confidence: 99%
See 4 more Smart Citations
“…One is the traditional k-folds cross-validation with scores in black colored font. e other is made with the functionality-based cross-validation approach in red colored font, used in Salem et al related work [53]. Besides, we use as a traditional single-model random-forest algorithm throughout all our studies.…”
Section: Preliminary Studiesmentioning
confidence: 99%
“…dispatch-methods for control-ow a ening or code virtualization). is approach is previously known as metadata recovery a acks [53].…”
Section: Introductionmentioning
confidence: 99%
See 3 more Smart Citations