Who Watches the Watchmen: A Security-focused Review on Current State-of-the-art Techniques, Tools, and Methods for Systems and Binary Analysis on Modern Platforms

被引:12
|
作者
Botacin, Marcus [1 ,3 ]
de Geus, Paulo Licio [1 ,3 ]
Gregio, Andre [2 ,4 ]
机构
[1] Univ Estadual Campinas, Campinas, SP, Brazil
[2] Univ Fed Parana, Curitiba, Parana, Brazil
[3] Ave Albert Einstein 1251,Cidade Univ Zeferino Vaz, BR-13083852 Campinas, SP, Brazil
[4] Rua Evaristo FF da Costa,383-391 Jardim Amer, BR-80050540 Curitiba, PR, Brazil
关键词
Binary analysis; malware; security; HVM; SMM; introspection;
D O I
10.1145/3199673
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malicious software, a threat users face on a daily basis, have evolved from simple bankers based on social engineering to advanced persistent threats. Recent research and discoveries reveal that malware developers have been using a wide range of anti-analysis and evasion techniques, in-memory attacks, and system subversion, including BIOS and hypervisors. In addition, code-reuse attacks like Returned Oriented Programming emerge as highly potential remote code execution threats. To counteract the broadness of malicious codes, distinct techniques and tools have been proposed, such as transparent malware tracers, system-wide debuggers, live forensics tools, and isolated execution rings. In this work, we present a survey on state-of-the-art techniques that detect, mitigate, and analyze the aforementioned attacks. We show approaches based on Hardware Virtual Machines introspection, System Management Mode instrumentation, Hardware Performance Counters, isolated rings (e.g., Software Guard eXtensions), as well as others based on external hardware. We also discuss upcoming threats based on the very same technologies used for defense. Our main goal is to provide the reader with a broader, more comprehensive understanding of recently surfaced tools and techniques aiming at binary analysis for modern platforms.
引用
收藏
页数:34
相关论文
共 6 条
  • [1] State-of-the-art Tools and Techniques for Quantitative Modeling and Analysis of Embedded Systems
    Bozga, Marius
    David, Alexandre
    Hartmanns, Arnd
    Hermanns, Holger
    Larsen, Kim G.
    Legay, Axel
    Tretmans, Jan
    DESIGN, AUTOMATION & TEST IN EUROPE (DATE 2012), 2012, : 370 - 375
  • [2] State-of-the-art violence detection techniques in video surveillance security systems: a systematic review
    Omarov, Batyrkhan
    Narynov, Sergazi
    Gumar, Aidana
    Khassanova, Mariyam
    Zhumanov, Zhandos
    PEERJ COMPUTER SCIENCE, 2022, 8
  • [3] State-of-the-art violence detection techniques in video surveillance security systems: A systematic review
    Omarov B.
    Narynov S.
    Zhumanov Z.
    Gumar A.
    Khassanova M.
    PeerJ Computer Science, 2022, 8
  • [4] A State-of-the-Art Review on Optimization Methods and Techniques for Economic Load Dispatch with Photovoltaic Systems: Progress, Challenges, and Recommendations
    Fahim, Khairul Eahsun
    De Silva, Liyanage C.
    Hussain, Fayaz
    Yassin, Hayati
    SUSTAINABILITY, 2023, 15 (15)
  • [5] The State-of-the-Art Review on Applications of Intrusive Sensing, Image Processing Techniques, and Machine Learning Methods in Pavement Monitoring and Analysis
    Hou, Yue
    Li, Qiuhan
    Zhang, Chen
    Lu, Guoyang
    Ye, Zhoujing
    Chen, Yihan
    Wang, Linbing
    Cao, Dandan
    ENGINEERING, 2021, 7 (06) : 845 - 856
  • [6] A state-of-the-art comprehensive review of modern control techniques for grid-connected wind turbines and photovoltaic arrays distributed generation systems
    Abdul Basit, Bilal
    Nguyen, Anh Tuan
    Ryu, Sang-Wook
    Park, Hyunghu
    Jung, Jin-Woo
    IET RENEWABLE POWER GENERATION, 2022, 16 (11) : 2191 - 2222