%0 Journal Article
%T Firm-code Disassembly Technology Based on IVT Reconstruction
基于中断向量表重构的固件代码反汇编技术
%A CUI Chen
%A LI Qing-bao
%A HU Gang
%A WANG Wei
%A
崔晨
%A 李清宝
%A 胡刚
%A 王炜
%J 计算机科学
%D 2012
%I
%X Disassembly is an important part of firmware reverse engineering analysis, whose correctness directly influences the precision of FREA. At present,most of the disassembly methods focus on practical program. However,these methods could not be directly used in firm-code disassembly due to its particularity. IV T (Interrupt Vector Fable) is the core of firm-code. Effective interrupt vectors are available by reconstructing the IVT. The more interrupt vectors we obtwin, the more precise the disassembly result is. The structural characteristics of firm-code were studied, and the IV T reconstruction method was introduced. Moreover, a disassembly technology based on the reconstruction of IVT was proposed. The experimental results show that the proposed technology can effectively improve the precision of firm-code disassembly, by which both of main function and interrupt subprograms could be disassembled, compared with traditional static disassembly methods. The disassembly precision is increased by 8. 72 0 in average.
%K Reverse analysis
%K Firm-code
%K Disassembly
%K IVT
逆向分析
%K 固件代码
%K 反汇编
%K 中断向量表
%U http://www.alljournals.cn/get_abstract_url.aspx?pcid=5B3AB970F71A803DEACDC0559115BFCF0A068CD97DD29835&cid=8240383F08CE46C8B05036380D75B607&jid=64A12D73428C8B8DBFB978D04DFEB3C1&aid=A77A33C0E8506BAB60CD93A3D5695836&yid=99E9153A83D4CB11&vid=7C3A4C1EE6A45749&iid=DF92D298D3FF1E6E&sid=119B6C0AA09DE6B9&eid=89057088FCFD45CE&journal_id=1002-137X&journal_name=计算机科学&referenced_num=0&reference_num=0