3 ms·
My naive understanding is this approach is that there will be clear units that do small bits of work. With a tracing framework and some analysis, like that rece
by rainforest 13y ago
My naive understanding is this approach is that there will be clear units that do small bits of work. With a tracing framework and some analysis, like that recently presented at BH [1], I wonder if blocks of code could be extracted to remove some of the obfuscation - if the blocks are meaningful (or can be simplified).
Does anyone have any ideas if this sort of analysis looks feasible in response to this kind of obfuscation?
[1] : [PDF] - https://media.blackhat.com/us-13/US-13-Raber-Virtual-Deobfuscator-A-DARPA-Cyber-Fast-Track-Funded-Effort-Slides.pdf https://media.blackhat.com/us-13/US-13-Raber-Virtual-Deobfus...