Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study
Khaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew Smith
Abstract
Analysis of malicious software is an essential task in computer security, it provides the necessary understanding to devise effective countermeasures and mitigation strategies. The level of sophistication and complexity of current malware continues to evolve significantly, as the recently discovered "Regin" malware family strikingly illustrates. This complexity makes the already tedious and time-consuming task of manual malware reverse engineering even more difficult and challenging. Decompilation can accelerate this process by enabling analysts to reason about a high-level, more abstract from of binary code. While significant advances have been made, state-of-the-art decompilers still produce very complex and unreadable code and malware analysts still frequently go back to analyzing the assembly code. In this paper, we present several semantics-preserving code transformations to make the decompiled code more readable, thus helping malware analysts understand and combat malware. We have implemented our optimizations as extensions to the academic decompiler DREAM. To evaluate our approach, we conducted the first user study to measure the quality of decompilers for malware analysis. Our study includes 6 analysis tasks based on real malware samples we obtained from independent malware experts. We evaluate three decompilers: the leading industry decompiler Hex-Rays, the state-of-the-art academic decompiler DREAM, and our usability-optimized decompiler DREAM++. The results show that our readability improvements had a significant effect on how well our participants could analyze the malware samples. DREAM++ outperforms both Hex-Rays and DREAM significantly. Using DREAM++ participants solved 3x more tasks than when using Hex-Rays and 2x more tasks than when using DREAM.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f901f6b0-6e53-4f67-8526-35970348f0b0Cited by top-tier papers36
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 114 citations
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
- Elipmoc: advanced decompilation of Ethereum smart contractsNeville Grech, Sifis Lagouvardos, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2022 · 40 citations
- A Usability Evaluation of Let's Encrypt and Certbot: Usable Security Done RightChristian Tiefenau, Emanuel von Zezschwitz, Maximilian Häring, Katharina Krombholz et al.CCS 2019 · 37 citations
Related papers
- Evaluating the Effectiveness of DecompilersYing Cao, Runze Zhang, Ruigang Liang, Kai ChenISSTA 2024 · 10 citations
- R2I: A Relative Readability Metric for Decompiled CodeHaeun Eom, Dohee Kim, Sori Lim, Hyungjoon Koo et al.FSE 2024 · 6 citations
- How far we have come: testing decompilation correctness of C decompilersZhibo Liu, Shuai WangISSTA 2020 · 53 citations
- Pyfet: Forensically Equivalent Transformation for Python Binary DecompilationAli Ahad, Chijung Jung, Ammar Askar, Doowon Kim et al.S&P 2023
- Decomperson: How Humans Decompile and What We Can Learn From ItKevin Burk, Fabio Pagani, Christopher Kruegel, Giovanni VignaUSENIX Security 2022
