Skip to main navigation Skip to search Skip to main content

Function Grouping & Visualization Through Machine Learning to Aid and Automate Reverse Engineering of Malware

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Modern malware analysis is stymied by dependence on the manual components of reverse engineering, which require skilled reverse engineers to perform static analysis. Machine learning and statistical analysis allow for augmentation of static analysis, detection of common benign code in malicious samples, and grouping similar bodies of low-level code. In this work four malware campaigns along with a dataset of known benign executables were utilized to test a process for grouping nearly identical functions to find similarities across executables and identify common code. In addition, those groups were collated to create sets of shared common code which could be used to better understand malware sample variants.

Original languageEnglish
Title of host publication2022 Resilience Week, RWS 2022 - Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781665488198
ISBN (Print)9781665488198
DOIs
StatePublished - Dec 20 2022
Event2022 Resilience Week, RWS 2022 - National Harbor, United States
Duration: Sep 26 2022Sep 29 2022

Publication series

Name2022 Resilience Week, RWS 2022 - Proceedings

Conference

Conference2022 Resilience Week, RWS 2022
Country/TerritoryUnited States
CityNational Harbor
Period09/26/2209/29/22

Keywords

  • Cyber Security
  • Malware Analysis
  • Ransomware

INL Publication Number

  • INL/CON-22-67754
  • 135550

Fingerprint

Dive into the research topics of 'Function Grouping & Visualization Through Machine Learning to Aid and Automate Reverse Engineering of Malware'. Together they form a unique fingerprint.

Cite this