Inspecting Virtual Machine Diversification Inside Virtualization Obfuscation
Naiqian Zhang, Dongpeng Xu, Jiang Ming, Jun Xu, Qiaoyan Yu
摘要
Virtualization obfuscators are commonly employed to safeguard proprietary code or to impede malware analysis. Despite significant efforts to combat these obfuscators over the past decade, code virtualization continues to be an exceedingly effective obfuscation technique. At the core of modern virtualization obfuscators are the virtual machines (VMs), which employ a variety of diversification techniques to complicate their internal structures. Due to its intricate and diverse nature, reverse engineering one VM is a time-consuming task and is not useful in cracking other VMs. Yet, despite the success of these VMs, there has been no systematic study of their diversification techniques, creating a knowledge gap that needs to be addressed to enhance VM deobfuscation. This work aims to bridge the above gap. First, we categorize and unveil the techniques under the hood of VM diversification, from the perspectives of VM interpretation, byte-code organization, and handler permutation/relocation. This systematic knowledge about modern virtualization is a crucial contribution to the field. Second, we develop an automated tool to identify the VM diversification techniques adopted by state-of-the-art virtualization obfuscators. The results demystify how the VM diversification methods are deployed in practice. Third, our research also involves patching current deobfuscation tools using the newly revealed knowledge of VM diversification to overcome their weaknesses. This outcome highlights how the results of our study pave the way for next-generation VM deobfuscation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper6
- BinSim: Trace-based Semantic Binary Diffing via System Call Sliced Segment Equivalence CheckingJiang Ming, Dongpeng Xu, Yufei Jiang, Dinghao WuUSENIX Security 2017 · 被引用 118 次
- Syntia: Synthesizing the Semantics of Obfuscated CodeTim Blazytko, Moritz Contag, Cornelius Aschermann, Thorsten HolzUSENIX Security 2017 · 被引用 99 次
- Predicting the Resilience of Obfuscated Code Against Symbolic Execution Attacks via Machine LearningSebastian Banescu, Christian S. Collberg, Alexander PretschnerUSENIX Security 2017 · 被引用 55 次
- MBA-Blast: Unveiling and Simplifying Mixed Boolean-Arithmetic ObfuscationBinbin Liu, Junfu Shen, Jiang Ming, Qilong Zheng 等USENIX Security 2021 · 被引用 37 次
- Loki: Hardening Code Obfuscation Against Automated AttacksMoritz Schloegel, Tim Blazytko, Moritz Contag, Cornelius Aschermann 等USENIX Security 2022
相关 Paper
- Chosen-Instruction Attack Against Commercial Code Virtualization ObfuscatorsShijia Li, Chunfu Jia, Pengda Qiu, Qiyuan Chen 等NDSS 2022
- VMHunt: A Verifiable Approach to Partially-Virtualized Binary Code SimplificationDongpeng Xu, Jiang Ming, Yu Fu, Dinghao WuCCS 2018 · 被引用 60 次
- Parema: an unpacking framework for demystifying VM-based Android packersLei Xue, Yuxiao Yan, Luyi Yan, Muhui Jiang 等ISSTA 2021 · 被引用 11 次
- Tackling runtime-based obfuscation in Android with TIROMichelle Y. Wong, David LieUSENIX Security 2018 · 被引用 59 次
- Forced Execution for Malware Protected by Commercial Virtualization ObfuscatorsYifei Zhan, Yukun Cui, Shuofeng Hao, Dongnan He 等CCS 2026
