Software fingerprinting for automated assembly code analysis / P. Charland. : D68-2/27-2015E-PDF
With the revolution in information technology, the dependence of the Canadian Armed Forces (CAF) on their information systems continues to grow. While information systems-based assets confer a distinct advantage, they also make the CAF vulnerable if adversaries interfere with those. Unfortunately, the technology required to disrupt and damage an information system through malicious software (malware) is far less sophisticated and expensive than the amount of investment required to create the system. To understand and mitigate this threat, reverse engineering has to be performed to analyze malware. However, software reverse engineering is a manually intensive and time-consuming process. The learning curve to master it is quite steep and once mastered, the process is hindered when anti-reverse engineering techniques are used. This results in the very few available reverse engineers being quickly saturated. This Scientific Report describes new approaches to accelerate the reverse engineering process of malware. The goal is to reduce redundant analysis efforts by automating the identification of code fragments which reuse (i) previously analyzed assembly code or (ii) open source code publicly available.
Lien permanent pour cette publication :
publications.gc.ca/pub?id=9.807445&sl=1
Ministère/Organisme | Defence R&D Canada. |
---|---|
Titre | Software fingerprinting for automated assembly code analysis / P. Charland. |
Titre de la série | Scientific report ; 2015-R027 |
Type de publication | Série - Voir l'enregistrement principal |
Langue | [Anglais] |
Format | Électronique |
Document électronique | |
Note(s) | March 2015. Includes bibliographical references (p. 23-26). |
Information sur la publication | [Ottawa] : Defence Research and Development Canada, 2015. |
Auteur / Contributeur | Charland, P. |
Description | vii, 28, [2] p. : fig., tables. |
Numéro de catalogue |
|
Numéro de catalogue du ministère | DRDC-RDDC-2015-R027 |
Descripteurs | Computer security |
Demander des formats alternatifs
Pour demander une publication dans un format alternatif, remplissez le formulaire électronique des publications du gouvernement du Canada. Utilisez le champ du formulaire «question ou commentaire» pour spécifier la publication demandée.- Date de modification :