Software fingerprinting for automated assembly code analysis / P. Charland. : D68-2/27-2015E-PDF

With the revolution in information technology, the dependence of the Canadian Armed Forces (CAF) on their information systems continues to grow. While information systems-based assets confer a distinct advantage, they also make the CAF vulnerable if adversaries interfere with those. Unfortunately, the technology required to disrupt and damage an information system through malicious software (malware) is far less sophisticated and expensive than the amount of investment required to create the system. To understand and mitigate this threat, reverse engineering has to be performed to analyze malware. However, software reverse engineering is a manually intensive and time-consuming process. The learning curve to master it is quite steep and once mastered, the process is hindered when anti-reverse engineering techniques are used. This results in the very few available reverse engineers being quickly saturated. This Scientific Report describes new approaches to accelerate the reverse engineering process of malware. The goal is to reduce redundant analysis efforts by automating the identification of code fragments which reuse (i) previously analyzed assembly code or (ii) open source code publicly available.

Lien permanent pour cette publication :
publications.gc.ca/pub?id=9.807445&sl=1

Renseignements sur la publication
Ministère/Organisme Defence R&D Canada.
Titre Software fingerprinting for automated assembly code analysis / P. Charland.
Titre de la série Scientific report ; 2015-R027
Type de publication Série - Voir l'enregistrement principal
Langue [Anglais]
Format Électronique
Document électronique
Note(s) March 2015.
Includes bibliographical references (p. 23-26).
Information sur la publication [Ottawa] : Defence Research and Development Canada, 2015.
Auteur / Contributeur Charland, P.
Description vii, 28, [2] p. : fig., tables.
Numéro de catalogue
  • D68-2/27-2015E-PDF
Numéro de catalogue du ministère DRDC-RDDC-2015-R027
Descripteurs Computer security
Demander des formats alternatifs
Pour demander une publication dans un format alternatif, remplissez le formulaire électronique des publications du gouvernement du Canada. Utilisez le champ du formulaire «question ou commentaire» pour spécifier la publication demandée.
Date de modification :