Detail publikace

A Novel Approach to Online Retargetable Machine-Code Decompilation

ĎURFINA, L. KŘOUSTEK, J. MATULA, P. ZEMEK, P.

Originální název

A Novel Approach to Online Retargetable Machine-Code Decompilation

Typ

článek v časopise - ostatní, Jost

Jazyk

angličtina

Originální abstrakt

Machine-code decompilation, belonging to the area of reverse engineering, has found its applications in many real-world areas. Analysis of malicious software, search for vulnerabilities, and source-code recovery are some of the most important uses. As there exists a diversity of different platforms on which software can be run, an existence of a generic decompiler would be highly appreciated. This paper presents an extended version of our retargetable decompiler that also allows decompilation of raw binary code, such as firmware or code snippets. More specifically, in the present paper, we provide a description of a retargetable decompiler that is being developed within the Lissom project. First, we give an introduction into the area of machine-code decompilation, including a brief discussion of existing tools. Then, we describe the concept and architecture of the decompiler. As it is available in the form of a web service, we also provide its description. Finally, we summarise our results, present a case study of using the tool for analysing malicious software, and conclude the paper by several remarks on future research.

Klíčová slova

reverse engineering, decompilation, retargetable decompiler, raw machine code, code snippets, web service, Lissom

Autoři

ĎURFINA, L.; KŘOUSTEK, J.; MATULA, P.; ZEMEK, P.

Rok RIV

2014

Vydáno

26. 9. 2014

ISSN

2160-2174

Periodikum

Journal of Network and Innovative Computing (JNIC)

Ročník

2

Číslo

1

Stát

Spojené státy americké

Strany od

224

Strany do

232

Strany počet

9

URL

BibTex

@article{BUT111623,
  author="Lukáš {Ďurfina} and Jakub {Křoustek} and Peter {Matula} and Petr {Zemek}",
  title="A Novel Approach to Online Retargetable Machine-Code Decompilation",
  journal="Journal of Network and Innovative Computing (JNIC)",
  year="2014",
  volume="2",
  number="1",
  pages="224--232",
  issn="2160-2174",
  url="http://www.mirlabs.net/jnic/secured/Volume2-Issue1/Paper24/JNIC_Paper24.pdf"
}