earticle

논문검색

Culture Information Technology (CIT)

Performance Evaluation of Jump Displacement Technique on Benign PE files through IDA Pro

초록

한국어

Jump displacement is regarded as part of instruction displacement, which can be used for code diversification and code randomization. In this paper, we implement jump displacement technique on benign PE (Portable Executable) files through IDA Pro 7.0 in Windows systems. We then evaluate the performance of Jump displacement technique. More specifically, we implement jump displacement technique on 30 benign PE files and perform evaluation of them through IDA Pro 7.0. Our evaluation results demonstrate that jump displacement can cause an increase in the number of anti-virus engines misclassifying benign PE files as malware. Moreover, we discern that the larger number of machine codes affected by jump displacement technique in benign PE files can lead to the higher chance that IDA Pro 7.0 fails to disassemble correctly benign PE files, leading to malfunction of benign PE files.

목차

Abstract
1. Introduction
2. Related Work
3. Implementation of Jump Displacement Technique on Benign PE files
4. Performance Evaluation
5. Conclusion
Acknowledgement
References

저자정보

  • Jun-Won Ho Professor, Division of Intelligent Information Security, Seoul Women‘s University, South Korea

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.