Research Article

All-in-One Framework for Detection, Unpacking, and Verification for Malware Analysis

Table 1

Observations and solutions for the proposed all-in-one unpacking system.

ObservationExplanationSolution

No phase integrationUnpacking-related three phases are separately developedAdopt an all-in-one approach integrating all three phases

No detection combinationThere is no attempt to combine various existing methods for packing detectionCombine four packing detection methods to improve detection accuracy

No real-restorationMain goal is to find OEPRestore unpacked files by performing actual unpacking as well as finding OEP

No unpacking verificationThere is no quantitative way to verify the restoration accuracyPresent a verification algorithm to evaluate the accuracy of unpacking results