Automatic Reverse Engineering of Script Engine Binaries for Building Script API Tracers


연구 분야: Analysis



학회: Digital Threats: Research and Practice , Volume 2, Issue 1


초록

Script languages are designed to be easy-to-use and require low learning costs. These features provide attackers options to choose a script language for developing their malicious scripts. This diversity of choice in the attacker side unexpectedly imposes a significant cost on the preparation for analysis tools in the defense side. That is, we have to prepare for multiple script languages to analyze malicious scripts written in them. We call this unbalanced cost for script languages asymmetry problem. To solve this problem, we propose a method for automatically detecting the hook and tap points in a script engine binary that is essential for building a script Application Programming Interface (API) tracer. Our method allows us to reduce the cost of reverse engineering of a script engine binary, which is the largest portion of the development of a script API tracer, and build a script API tracer for a script language with minimum manual intervention. This advantage results in solving the asymmetry problem. The experimental results showed that our method generated the script API tracers for the three script languages popular among attackers (Visual Basic for Applications (VBA), Microsoft Visual Basic Scripting Edition (VBScript), and PowerShell). The results also demonstrated that these script API tracers successfully analyzed real-world malicious scripts.


Author Profile
Toshinori Usui

NTT Secure Platform Laboratories/Institute of Industrial Science The University of Tokyo Tokyo Japan

Japan
Author Profile
Yuto Otsuki

NTT Secure Platform Laboratories Japan

Japan
Author Profile
Tomonori Ikuse

NTT Secure Platform Laboratories Japan

Japan

📄 논문 정보

발행 연도 2021년
인용수 1
출판 국가 Japan
사이트 ACM
좋아요 수 0

연관 논문 목록 (206건)