@article{ART002794980},
author={Duhyeuk Chang and Seon-Min Kim and Junyoung Heo},
title={Extraction Scheme of Function Information in Stripped Binaries using LSTM},
journal={Journal of Software Assessment and Valuation},
issn={2092-8114},
year={2021},
volume={17},
number={2},
pages={39-46},
doi={10.29056/jsav.2021.12.05}
TY - JOUR
AU - Duhyeuk Chang
AU - Seon-Min Kim
AU - Junyoung Heo
TI - Extraction Scheme of Function Information in Stripped Binaries using LSTM
JO - Journal of Software Assessment and Valuation
PY - 2021
VL - 17
IS - 2
PB - Korea Software Assessment and Valuation Society
SP - 39
EP - 46
SN - 2092-8114
AB - To analyze and defend malware codes, reverse engineering is used as identify function location information. However, the stripped binary is not easy to find information such as function location because function symbol information is removed. To solve this problem, there are various binary analysis tools such as BAP and BitBlaze IDA Pro, but they are based on heuristics method, so they do not perform well in general. In this paper, we propose a technique to extract function information using LSTM-based models by applying algorithms of N-byte method that is extracted binaries corresponding to reverse assembling instruments in a recursive descent method. Through experiments, the proposed techniques were superior to the existing techniques in terms of time and accuracy.
KW - Bidrectional RNN;Function information;Machine Learning;N-byte;RNN;Reverse Engineering;Stripped Binary
DO - 10.29056/jsav.2021.12.05
ER -
Duhyeuk Chang, Seon-Min Kim and Junyoung Heo. (2021). Extraction Scheme of Function Information in Stripped Binaries using LSTM. Journal of Software Assessment and Valuation, 17(2), 39-46.
Duhyeuk Chang, Seon-Min Kim and Junyoung Heo. 2021, "Extraction Scheme of Function Information in Stripped Binaries using LSTM", Journal of Software Assessment and Valuation, vol.17, no.2 pp.39-46. Available from: doi:10.29056/jsav.2021.12.05
Duhyeuk Chang, Seon-Min Kim, Junyoung Heo "Extraction Scheme of Function Information in Stripped Binaries using LSTM" Journal of Software Assessment and Valuation 17.2 pp.39-46 (2021) : 39.
Duhyeuk Chang, Seon-Min Kim, Junyoung Heo. Extraction Scheme of Function Information in Stripped Binaries using LSTM. 2021; 17(2), 39-46. Available from: doi:10.29056/jsav.2021.12.05
Duhyeuk Chang, Seon-Min Kim and Junyoung Heo. "Extraction Scheme of Function Information in Stripped Binaries using LSTM" Journal of Software Assessment and Valuation 17, no.2 (2021) : 39-46.doi: 10.29056/jsav.2021.12.05
Duhyeuk Chang; Seon-Min Kim; Junyoung Heo. Extraction Scheme of Function Information in Stripped Binaries using LSTM. Journal of Software Assessment and Valuation, 17(2), 39-46. doi: 10.29056/jsav.2021.12.05
Duhyeuk Chang; Seon-Min Kim; Junyoung Heo. Extraction Scheme of Function Information in Stripped Binaries using LSTM. Journal of Software Assessment and Valuation. 2021; 17(2) 39-46. doi: 10.29056/jsav.2021.12.05
Duhyeuk Chang, Seon-Min Kim, Junyoung Heo. Extraction Scheme of Function Information in Stripped Binaries using LSTM. 2021; 17(2), 39-46. Available from: doi:10.29056/jsav.2021.12.05
Duhyeuk Chang, Seon-Min Kim and Junyoung Heo. "Extraction Scheme of Function Information in Stripped Binaries using LSTM" Journal of Software Assessment and Valuation 17, no.2 (2021) : 39-46.doi: 10.29056/jsav.2021.12.05