RUS  ENG
Full version
JOURNALS // Prikladnaya Diskretnaya Matematika. Supplement // Archive

Prikl. Diskr. Mat. Suppl., 2024 Issue 17, Pages 131–134 (Mi pdma663)

Mathematical Foundations of Computer Science and Computer Security

Using ELF relocations for executable encryption

R. K. Lebedev, V. E. Sitnov

Novosibirsk State University

Abstract: A new approach to hiding the code of Linux executable files using a relocation table is proposed, which allows you to create a crypter without embedding the decryption code in the executable file. Various applications of this approach are evaluated and the respective crypter prototypes are implemented. The dangers of this approach for the reverse engineering tools IDA, Ghidra, angr, as well as for antivirus software are assessed.

Keywords: packer, crypter, malware, relocation table, ELF.

UDC: 004.056.5

DOI: 10.17223/2226308X/17/33



© Steklov Math. Inst. of RAS, 2024