Hindawi Security and Communication Networks Volume 2019, Article ID 5278137, 16 pages https://doi.org/10.1155/2019/5278137 Research Article All-in-One Framework for Detection, Unpacking, and Verification for Malware Analysis Mi-Jung Choi , Jiwon Bang , Jongwook Kim, Hajin Kim, and Yang-Sae Moon Department of Computer Science, Kangwon National University, 1 Kangwondaehak-gil, Chuncheon-si, Gangwon 24341, Republic of Korea Correspondence should be addressed to Yang-Sae Moon;
[email protected] Received 10 April 2019; Revised 21 August 2019; Accepted 5 September 2019; Published 13 October 2019 Academic Editor: Jes´u sD´ıaz-Verdejo Copyright © 2019 Mi-Jung Choi et al. is is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. Packing is the most common analysis avoidance technique for hiding malware. Also, packing can make it harder for the security researcher to identify the behaviour of malware and increase the analysis time. In order to analyze the packed malware, we need to perform unpacking rst to release the packing. In this paper, we focus on unpacking and its related technologies to analyze the packed malware. rough extensive analysis on previous unpacking studies, we pay attention to four important drawbacks: no phase integration, no detection combination, no real-restoration, and no unpacking verication. To resolve these four drawbacks, in this paper, we present an all-in-one structure of the unpacking system that performs packing detection, unpacking (i.e., res- toration), and verication phases in an integrated framework.