skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Finding Cryptography in Object Code

Conference ·
OSTI ID:946857

Finding and identifying Cryptography is a growing concern in the malware analysis community. In this paper, a heuristic method for determining the likelihood that a given function contains a cryptographic algorithm is discussed and the results of applying this method in various environments is shown. The algorithm is based on frequency analysis of opcodes that make up each function within a binary.

Research Organization:
Idaho National Lab. (INL), Idaho Falls, ID (United States)
Sponsoring Organization:
USDOE
DOE Contract Number:
DE-AC07-99ID-13727
OSTI ID:
946857
Report Number(s):
INL/CON-08-14597; TRN: US200903%%1013
Resource Relation:
Conference: SecTor 2008,Toronto, CA,10/07/2008,10/08/2008
Country of Publication:
United States
Language:
English