Decoder-free sino-Korean shellcode

Cited 1 time in webofscience Cited 0 time in scopus
  • Hit : 55
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorYoon, Ji Hyeonko
dc.contributor.authorKye, Jeong Ohko
dc.contributor.authorKim, Yeong-Daeko
dc.contributor.authorLee, Hae Youngko
dc.date.accessioned2023-08-23T02:01:46Z-
dc.date.available2023-08-23T02:01:46Z-
dc.date.created2023-07-06-
dc.date.issued2016-08-
dc.identifier.citation2016 International Conference on Software Security and Assurance, ICSSA 2016, pp.75 - 78-
dc.identifier.urihttp://hdl.handle.net/10203/311752-
dc.description.abstractSome researchers have recently showed that shellcode, a small piece of executable machine code, could be transformed into text. Although such shellcode-embedding text itself may elude defensive measures, due to the existence of a decoding routine attached the shellcode, it could be detected by them. In this paper, we propose a novel approach to building shellcode-embedding Korean text without a decoder and a list of addresses used for a code reuse attack. For shellcode that only makes system calls, some instructions can be replaced with equivalent ones and padded with the NOP instructions, in order to make the shellcode seen as Chinese characters on text editors having support for UTF-16. Gadgets, divided from the shellcode, carrying code to link them together, are then embedded into Korean text. Finally, shellcode-embedding Korean text can be obtained. Since the text does not have any routine for decoding and an address list used in a code reuse attack, it may be able to elude most defensive measures. A proof-of-concept that automates the production of decoder-free Korean shellcode has been implemented.-
dc.languageEnglish-
dc.publisherInstitute of Electrical and Electronics Engineers Inc.-
dc.titleDecoder-free sino-Korean shellcode-
dc.typeConference-
dc.identifier.wosid000400774600015-
dc.identifier.scopusid2-s2.0-85015891077-
dc.type.rimsCONF-
dc.citation.beginningpage75-
dc.citation.endingpage78-
dc.citation.publicationname2016 International Conference on Software Security and Assurance, ICSSA 2016-
dc.identifier.conferencecountryAU-
dc.identifier.conferencelocationSt Polten-
dc.identifier.doi10.1109/ICSSA.2016.21-
dc.contributor.localauthorYoon, Ji Hyeon-
dc.contributor.nonIdAuthorKye, Jeong Oh-
dc.contributor.nonIdAuthorKim, Yeong-Dae-
dc.contributor.nonIdAuthorLee, Hae Young-
Appears in Collection
RIMS Conference Papers
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 1 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0