A Task Analysis of Static Binary Reverse Engineering for Security

dc.contributor.authorNyre-Yu, Megan
dc.contributor.authorButler, Karin
dc.contributor.authorBolstad, Cheryl
dc.date.accessioned2021-12-24T17:37:35Z
dc.date.available2021-12-24T17:37:35Z
dc.date.issued2022-01-04
dc.description.abstractSoftware is ubiquitous in society, but understanding it, especially without access to source code, is both non-trivial and critical to security. A specialized group of cyber defenders conducts reverse engineering (RE) to analyze software. The expertise-driven process of software RE is not well understood, especially from the perspective of workflows and automated tools. We conducted a task analysis to explore the cognitive processes that analysts follow when using static techniques on binary code. Experienced analysts were asked to statically find a vulnerability in a small binary that could allow for unverified access to root privileges. Results show a highly iterative process with commonly used cognitive states across participants of varying expertise, but little standardization in process order and structure. A goal-centered analysis offers a different perspective about dominant RE states. We discuss implications about the nature of RE expertise and opportunities for new automation to assist analysts using static techniques.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2022.275
dc.identifier.isbn978-0-9981331-5-7
dc.identifier.urihttp://hdl.handle.net/10125/79608
dc.language.isoeng
dc.relation.ispartofProceedings of the 55th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCyber Deception and Cyberpsychology for Defense
dc.subjectcybersecurity
dc.subjectreverse engineering
dc.subjectcognitive process
dc.subjectautomation
dc.titleA Task Analysis of Static Binary Reverse Engineering for Security
dc.type.dcmitext

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0218.pdf
Size:
1.11 MB
Format:
Adobe Portable Document Format