Optimizing symbolic execution for malware behavior classification

Sebastio, Stefano;Baranov, Eduard;Biondi, Fabrizio;Decourbe, Olivier;Quilbeuf, Jean;et.al.
(2020) Computers & Security — Vol. 93, n° ?, p. 101775 (2020)

Files

angrOptTune_main_elsarticle.pdf
  • Open Access
  • Adobe PDF
  • 13.39 MB

Details

Authors
  • Sebastio, Stefanoorcid-logo
    Author
  • Author
  • Biondi, Fabrizio
    Author
  • Decourbe, Olivier
    Author
  • Given-Wilson, ThomasUCLouvain
    Author
  • Legay, AxelUCLouvain
    Author
  • Quilbeuf, Jean
    Author
Show more
Abstract
Increasingly software correctness, reliability, and security is being analyzed using tools that combine various formal and heuristic approaches. Often such analysis becomes expensive in terms of time and at the cost of high quality results. In this experience report we explore the tuning and optimization of the tools underlying binary malware detection and classification. We identify heuristics and SMT solver tactics for the effective symbolic execution of binary files. We combine these with effective heuristics for the construction of behavioral signatures of programs that can be used for a supervised learning multi-class malware classifier. Further, a set of experiments following the full-factorial design allowed us to identify the correlations between heuristics and the overall performance of the classifier.
Affiliations

Citations

Sebastio, S., Baranov, E., Biondi, F., Decourbe, O., Given-Wilson, T., Legay, A., Puodzius, C., & Quilbeuf, J. (2020). Optimizing symbolic execution for malware behavior classification. Computers & Security, 93(?), 101775. https://doi.org/10.1016/j.cose.2020.101775 (Original work published 2020)