Research Article

BAHK: Flexible Automated Binary Analysis Method with the Assistance of Hardware and System Kernel

Table 1

Other results by the first specific analysis approach.

ProgramNumber of EPT violations (million)Proportion of simple paths (%)Processor time (PM-FI)Physical memory occupation (PM-FI)Execution time of PM (s)

Tasklist16.89124%-24%53M-41M10.2
Systeminfo6.98822%-24%51M-37M9.3
Certutil25.39225%-25%45M-36M7.2
Notepad9.18718%-19%84M-42M20
XPS16.68922%-23%90M-44M21
FFmpeg34.89121%-24%64M-45M11.2
WinRAR201.19828%-65%92M-85M9.7
Curl8.99416%-21%33M-35M9.0