• Home
  • Search
  • Extracting Sent Message Formats from Executables Using Backward Slicing
  • Cite Icon14
  • https://doi.org/10.1109/eidwt.2013.71Copy DOI Icon

Extracting Sent Message Formats from Executables Using Backward Slicing

  • Sep 1, 2013
  • Min Liu +3 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Network communication protocol reverse-engineering is important for malicious software analysis. Security analysts need to rewrite messages sent and received by malicious software according to the protocol to control the malware's malicious behaviors. To enable such rewriting, we need detailed information about the sent message by the malware program in target host in the network dialog. However, recent works on sent message extraction have limitations and the source code of malware program is usually not obtained. This paper proposes an analysis method to extract sent message format by processing executables. This paper obtains the reliable execution trace of malware program firstly, then gets the syntax structure of the send buffer of sent function combining the binary code analysis technique with the binary dynamic backward program slicing technique. Finally we exploit the dynamic taint analysis to extract the semantic information of different syntax fields. The experimental results show that our analysis framework can effectively analyze format information of malware's sent message.

Similar Papers
  • Conference Article
  • Citations111

Identifying Dormant Functionality in Malware Programs

  • Jan 01, 2010
  • Paolo Milani Comparetti +5
  • Research Article

Construction of a Cybersecurity Behavior Knowledge Base for Malicious Behavior Analysis

  • Dec 30, 2024
  • Research Briefs on Information and Communication Technology Evolution
  • Keke Feng +4
  • Conference Article
  • Citations307

Mining specifications of malicious behavior

  • Sep 07, 2007
  • Mihai Christodorescu +2
  • Research Article
  • Citations9

Malicious-Behavior-Aware D2D Link Selection Mechanism

  • Jan 01, 2017
  • IEEE Access
  • Ruyan Wang +4
  • Conference Article
  • Citations1

Remote Injected Code Behavior Analysis using Code Refactor

  • Jun 24, 2022
  • Qian Zhang +3
  • Conference Article
  • Citations1

Malicious Code Detection Based on Software Fingerprint

  • Jan 01, 2013
  • Zhimin Yin +2
  • Research Article
  • Citations1

Pre-trained Behavioral Model for Malicious User Prediction on Social Platform

  • Apr 11, 2025
  • Proceedings of the AAAI Conference on Artificial Intelligence
  • Meng Jiang +5
  • Conference Article
  • Citations33

Early detection of malicious behavior in JavaScript code

  • Oct 19, 2012
  • Kristof Schütt +3
  • Research Article
  • Citations27

The other guys: automated analysis of marginalized malware

  • Feb 27, 2017
  • Journal of Computer Virology and Hacking Techniques
  • Marcus Felipe Botacin +2
  • Book Chapter
  • Citations7

Classification of Malicious Software Behaviour Detection with Hybrid Set Based Feed Forward Neural Network

  • Jan 01, 2010
  • Yong Wang +4
  • Research Article

ВЫЯВЛЕНИЕ СКРЫТЫХ УЯЗВИМОСТЕЙ В ИСХОДНОМ КОДЕ МНОГОПОТОЧНЫХ ПРОГРАММ ПОСРЕДСТВОМ АНАЛИЗА ФУНКЦИОНАЛЬНЫХ ПЕРЕХОДОВ

  • Jan 01, 2020
  • Journal of the Ural Federal District. Information security
  • D A Morgunov
  • Research Article

Design of Malicious Code Detection System Based on Binary Code Slicing

  • Jun 01, 2022
  • 電腦學刊
  • Mohan Liu Mohan Liu +2
  • PDF
  • Research Article
  • Citations1

Explicit Effects and Effect Constraints in ReML

  • Jan 02, 2024
  • Proceedings of the ACM on Programming Languages
  • Martin Elsman
  • Conference Article
  • Citations4

Efficient Method for Analyzing Malicious Websites by Using Multi-Environment Analysis System

  • Aug 01, 2017
  • Masanori Hirotomo +5
  • Research Article
  • Citations4

Instrumentation and Software for Analysis of Arabidopsis Circadian Leaf Movement

  • Mar 31, 2009
  • Interdisciplinary Bio Central
  • Jeong-Sik Kim +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.