PackGenome: Automatically Generating Robust YARA Rules for Accurate Malware Packer Detection
Shijia Li, Jiang Ming, Pengda Qiu, Qiyuan Chen, Lanqing Liu, Huaifeng Bao, Qiang Wang, Chunfu Jia
摘要
Binary packing, a widely-used program obfuscation style, compresses or encrypts the original program and then recovers it at runtime. Packed malware samples are pervasive-they conceal arresting code features as unintelligible data to evade detection. To rapidly respond to large-scale packed malware, security analysts search specific binary patterns to identify corresponding packers. The quality of such packer patterns or signatures is vital to malware dissection. However, existing packer signature rules severely rely on human analysts' experience. In addition to expensive manual efforts, these human-written rules (e.g., YARA) also suffer from high false positives: as they are designed to search the pattern of bytes rather than instructions, they are very likely to mismatch with unexpected instructions. In this paper, we look into the weakness of existing packer detection signatures and propose a novel automatic YARA rule generation technique, called PackGenome. Inspired by the biological concept of species-specific genes, we observe that packer-specific genes can help determine whether a program is packed. Our framework generates new YARA rules from packer-specific genes, which are extracted from the unpacking routines reused in the samepacker protected programs. To reduce false positives, we propose a byte selection strategy to systematically evaluate the mismatch possibility of bytes. We compare PackGenome with public-available packer signature collections and a state-of-the-art automatic rule generation tool. Our large-scale experiments with more than 640K samples demonstrate that PackGenome can deliver robust YARA rules to detect Windows and Linux packers, including emerging * Corresponding author.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Beyond Raw Bytes: Towards Large Malware Language ModelsLuke Kurlandski, Harel Berger, Yin Pan, Matthew WrightNDSS 2026 · 被引用 5 次
- Adversarially Robust Assembly Language Model for Packed Executables DetectionShijia Li, Jiang Ming, Lanqing Liu, Longwei Yang 等CCS 2025
它引用的顶会 Paper13
- Understanding Linux MalwareEmanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide BalzarottiS&P 2018 · 被引用 203 次
- Superset Disassembly: Statically Rewriting x86 Binaries Without HeuristicsErick Bauman, Zhiqiang Lin, Kevin W. HamlenNDSS 2018 · 被引用 112 次
- Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance BoostBinlin Cheng, Jiang Ming, Jianming Fu, Guojun Peng 等CCS 2018 · 被引用 68 次
- An Inside Look into the Practice of Malware AnalysisMiuyin Yong Wong, Matthew Landen, Manos Antonakakis, Douglas M. Blough 等CCS 2021 · 被引用 58 次
- DeepReflect: Discovering Malicious Functionality through Binary ReconstructionEvan Downing, Yisroel Mirsky, Kyuhong Park, Wenke LeeUSENIX Security 2021 · 被引用 43 次
相关 Paper
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin 等NDSS 2018 · 被引用 87 次
- YARIX: Scalable YARA-based Malware IntelligenceMichael Brengel, Christian RossowUSENIX Security 2021 · 被引用 23 次
- Parema: an unpacking framework for demystifying VM-based Android packersLei Xue, Yuxiao Yan, Luyi Yan, Muhui Jiang 等ISSTA 2021 · 被引用 11 次
- When Malware is Packin' Heat; Limits of Machine Learning Classifiers Based on Static Analysis FeaturesHojjat Aghakhani, Fabio Gritti, Francesco Mecca, Martina Lindorfer 等NDSS 2020
- Happer: Unpacking Android Apps via a Hardware-Assisted ApproachLei Xue, Hao Zhou, Xiapu Luo, Yajin Zhou 等S&P 2021 · 被引用 29 次
