摘要
首次对复合条件分支编译后的结构进行形式化描述,应用图论方法提出了复合分支网络概念,并在此基础上提出了一种新的识别算法。通过理论分析并采用该算法对多个典型样本进行实验,均显示该算法与现有算法相比,识别正确性有明显改善。
A novel recognition algorithm is proposed. Compared with previous works, the algorithm is deterministic rather than heuristic, and it does not use complicated data structures. The new algorithm is more accurate than typical current approaches; furthermore, the new method has been applied to several real-world binaries, and experimental results validate such theoretical analysis.
出处
《北京大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2008年第1期37-43,共7页
Acta Scientiarum Naturalium Universitatis Pekinensis
基金
国家"863"计划(2006AA01Z402)
电子发展基金(信部运[2006]634号)资助项目
关键词
逆向工程
信息安全
反编译
控制流分析
复合条件分支
reverse engineering
information security
decompilation
control flow analysis
compound condition