Generic unpacking using entropy analysis

Guhyeon Jeong, Euijin Choo, Joosuk Lee, Munkhbayar Bat-Erdene, Heejo Lee

    Research output: Chapter in Book/Report/Conference proceedingConference contribution

    31 Citations (Scopus)

    Abstract

    Malwares attempt to evade AV scanners using various obfuscation techniques. Packing is a popular obfuscation technique used by 80% of malwares. In this paper, we propose a generic unpacking mechanism to find the original entry point (OEP) using entropy analysis. The experiment using 110 packed executables demonstrates the proposed mechanism can locate the OEPs of 72% of the packed executables. Furthermore, we show how the mechanism could be applied to packed malwares.

    Original languageEnglish
    Title of host publicationProceedings of the 5th IEEE International Conference on Malicious and Unwanted Software, Malware 2010
    Pages98-105
    Number of pages8
    DOIs
    Publication statusPublished - 2010
    Event5th International Conference on Malicious and Unwanted Software, Malware 2010 - Nancy, France
    Duration: 2010 Oct 192010 Oct 20

    Publication series

    NameProceedings of the 5th IEEE International Conference on Malicious and Unwanted Software, Malware 2010

    Other

    Other5th International Conference on Malicious and Unwanted Software, Malware 2010
    Country/TerritoryFrance
    CityNancy
    Period10/10/1910/10/20

    ASJC Scopus subject areas

    • Software

    Fingerprint

    Dive into the research topics of 'Generic unpacking using entropy analysis'. Together they form a unique fingerprint.

    Cite this