Using ELF relocations for executable encryption
Prikladnaya Diskretnaya Matematika. Supplement, no. 17 (2024), pp. 131-134

Voir la notice de l'article provenant de la source Math-Net.Ru

A new approach to hiding the code of Linux executable files using a relocation table is proposed, which allows you to create a crypter without embedding the decryption code in the executable file. Various applications of this approach are evaluated and the respective crypter prototypes are implemented. The dangers of this approach for the reverse engineering tools IDA, Ghidra, angr, as well as for antivirus software are assessed.
Keywords: packer, malware, relocation table, ELF.
Mots-clés : crypter
@article{PDMA_2024_17_a32,
     author = {R. K. Lebedev and V. E. Sitnov},
     title = {Using {ELF} relocations for executable encryption},
     journal = {Prikladnaya Diskretnaya Matematika. Supplement},
     pages = {131--134},
     publisher = {mathdoc},
     number = {17},
     year = {2024},
     language = {ru},
     url = {http://geodesic.mathdoc.fr/item/PDMA_2024_17_a32/}
}
TY  - JOUR
AU  - R. K. Lebedev
AU  - V. E. Sitnov
TI  - Using ELF relocations for executable encryption
JO  - Prikladnaya Diskretnaya Matematika. Supplement
PY  - 2024
SP  - 131
EP  - 134
IS  - 17
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/PDMA_2024_17_a32/
LA  - ru
ID  - PDMA_2024_17_a32
ER  - 
%0 Journal Article
%A R. K. Lebedev
%A V. E. Sitnov
%T Using ELF relocations for executable encryption
%J Prikladnaya Diskretnaya Matematika. Supplement
%D 2024
%P 131-134
%N 17
%I mathdoc
%U http://geodesic.mathdoc.fr/item/PDMA_2024_17_a32/
%G ru
%F PDMA_2024_17_a32
R. K. Lebedev; V. E. Sitnov. Using ELF relocations for executable encryption. Prikladnaya Diskretnaya Matematika. Supplement, no. 17 (2024), pp. 131-134. http://geodesic.mathdoc.fr/item/PDMA_2024_17_a32/