{"doi":"10.1155/2019/5278137","title":"All-in-One Framework for Detection, Unpacking, and Verification for Malware Analysis","abstract":"<jats:p><jats:italic>Packing</jats:italic> is the most common analysis avoidance technique for hiding malware. Also, packing can make it harder for the security researcher to identify the behaviour of malware and increase the analysis time. In order to analyze the packed malware, we need to perform <jats:italic>unpacking</jats:italic> first to release the packing. In this paper, we focus on unpacking and its related technologies to analyze the packed malware. Through extensive analysis on previous unpacking studies, we pay attention to four important drawbacks: <jats:italic>no phase integration</jats:italic>, <jats:italic>no detection combination</jats:italic>, <jats:italic>no real-restoration</jats:italic>, and <jats:italic>no unpacking verification</jats:italic>. To resolve these four drawbacks, in this paper, we present an <jats:italic>all-in-one</jats:italic> structure of the unpacking system that performs packing detection, unpacking (i.e., restoration), and verification phases in an integrated framework. For this, we first greatly increase the packing detection accuracy in the detection phase by combining four existing and new packing detection techniques. We then improve the unpacking phase by using the state-of-the-art static and dynamic unpacking techniques. We also present a verification algorithm evaluating the accuracy of unpacking results. Experimental results show that the proposed all-in-one unpacking system performs all of the three phases well in an integrated framework. In particular, the proposed hybrid detection method is superior to the existing methods, and the system performs unpacking very well up to 100% of restoration accuracy for most of the files except for a few packers.</jats:p>","journal":"Security and Communication Networks","year":2019,"id":590825,"datarank":0.5549869368037689,"base_score":2.5649493574615367,"endowment":2.5649493574615367,"self_citation_contribution":0.38474240361923057,"citation_network_contribution":0.1702445331845383,"self_endowment_contribution":0.38474240361923057,"citer_contribution":0.1702445331845383,"corpus_percentile":null,"corpus_rank":null,"citation_count":12,"citer_count":9,"citers_with_citation_signal":4,"citers_with_endowment":4,"datacite_reuse_total":0,"is_dataset":false,"is_dataset_confidence":null,"is_data_producer":false,"deposit_databanks":null,"is_oa":false,"file_count":0,"downloads":0,"has_version_chain":false,"published_date":null,"fair_score":null,"fair_percentile":null,"algorithm_id":"datarank_citation_only_1hop_v6","ranking_scope":"data_only","authors":[{"id":1439580,"name":"Jiwon Bang","orcid":"0000-0002-2068-0942","position":1,"is_corresponding":false},{"id":1511581,"name":"Jongwook Kim","orcid":null,"position":2,"is_corresponding":false},{"id":1511582,"name":"Hajin Kim","orcid":null,"position":3,"is_corresponding":false},{"id":1511583,"name":"Yang-Sae Moon","orcid":"0000-0002-2396-0405","position":4,"is_corresponding":false},{"id":1511580,"name":"Mi-Jung Choi","orcid":"0000-0002-9062-4604","position":0,"is_corresponding":false}],"reference_count":0,"raw_metadata":{"has_enrichment":true,"resolved":true,"title":"All-in-One Framework for Detection, Unpacking, and Verification for Malware Analysis","abstract":"<jats:p><jats:italic>Packing</jats:italic> is the most common analysis avoidance technique for hiding malware. Also, packing can make it harder for the security researcher to identify the behaviour of malware and increase the analysis time. In order to analyze the packed malware, we need to perform <jats:italic>unpacking</jats:italic> first to release the packing. In this paper, we focus on unpacking and its related technologies to analyze the packed malware. Through extensive analysis on previous unpacking studies, we pay attention to four important drawbacks: <jats:italic>no phase integration</jats:italic>, <jats:italic>no detection combination</jats:italic>, <jats:italic>no real-restoration</jats:italic>, and <jats:italic>no unpacking verification</jats:italic>. To resolve these four drawbacks, in this paper, we present an <jats:italic>all-in-one</jats:italic> structure of the unpacking system that performs packing detection, unpacking (i.e., restoration), and verification phases in an integrated framework. For this, we first greatly increase the packing detection accuracy in the detection phase by combining four existing and new packing detection techniques. We then improve the unpacking phase by using the state-of-the-art static and dynamic unpacking techniques. We also present a verification algorithm evaluating the accuracy of unpacking results. Experimental results show that the proposed all-in-one unpacking system performs all of the three phases well in an integrated framework. In particular, the proposed hybrid detection method is superior to the existing methods, and the system performs unpacking very well up to 100% of restoration accuracy for most of the files except for a few packers.</jats:p>","is_dataset_classified":null,"base_score":2.5649493574615367,"endowment":2.5649493574615367,"datacite_reuse_total":0,"file_count":0,"downloads":0,"views":0,"has_version_chain":false,"is_dataset":false,"is_oa":false,"pmid":"20725694","pmcid":null,"openalex_id":"https://openalex.org/W2980032325","authors":[],"funders":[{"funder_name":"Ministry of Science, ICT and Future Planning","grant_id":"2017-0-00158","title":null},{"funder_name":"Ministry of Science, ICT and Future Planning","grant_id":"R18XA05","title":null}],"total_grants":2,"fwci":0.7741,"citation_percentile":0.73744316,"influential_citations":0,"citation_trend":[{"year":2020,"count":3},{"year":2021,"count":1},{"year":2022,"count":1},{"year":2023,"count":4},{"year":2024,"count":2},{"year":2025,"count":1}],"oa_status":"hybrid","license":"cc-by","oa_locations":[{"url":"https://downloads.hindawi.com/journals/scn/2019/5278137.pdf","host_type":"journal"},{"url":"https://downloads.hindawi.com/journals/scn/2019/5278137.pdf","host_type":"publisher"},{"url":"http://downloads.hindawi.com/journals/scn/2019/5278137.pdf","host_type":"publisher"},{"url":"http://downloads.hindawi.com/journals/scn/2019/5278137.xml","host_type":"publisher"},{"url":"https://doi.org/10.1155/2019/5278137","host_type":"journal"},{"url":"https://doaj.org/article/472055ac407d44dd8e47a1bd374cc2ee","host_type":"repository"}],"fields_of_study":["Advanced Malware Detection Techniques","Network Security and Intrusion Detection","Anomaly Detection Techniques and Applications"],"mesh_terms":[],"keywords":["Unpacking","Malware","Computer science","Malware analysis","Static analysis","Data mining","Computer security","Programming language"],"sdg_mappings":[],"linked_datasets":[],"clinical_trials":[],"software_tools":[],"database_accessions":[],"source":"live","citation_network_status":"fetched"},"created_at":"2026-07-25T12:32:37.920236Z","pmid":null,"pmcid":null,"fwci":null,"citation_percentile":null,"influential_citations":0,"oa_status":null,"license":null,"views":0,"total_file_size_bytes":0,"version_count":0,"fair_f":null,"fair_a":null,"fair_i":null,"fair_r":null,"fair_zscore":null,"fair_rationale":null,"fair_model":null,"fair_agent_version":null,"fair_fulltext_source":null,"fair_has_llm":null,"fair_computed_at":null,"clinical_trials":[],"software_tools":[],"db_accessions":[],"linked_datasets":[],"topics":[]}