Reverse Engineering Basics
Reverse engineering involves analyzing software to understand its behavior, structure, and potential vulnerabilities. This section covers foundational concepts critical to malware analysis and defensive security: memory analysis, file formats (PE/ELF), and the distinction between static and dynamic analysis. These principles underpin tools like Ghidra, which enable deep inspection of malicious code.
Memory Analysis¶
Memory analysis focuses on examining a program's runtime state, including loaded modules, data structures, and execution flow. Tools like Ghidra provide memory viewers to inspect address spaces, identify code regions, and track dynamic behavior.
Key concepts:
- Memory regions: Code, stack, heap, and data segments.
- Address spaces: Virtual memory layout of processes.
- Memory dumps: Captures of process memory for post-mortem analysis.
Example: Use Ghidra’s memory viewer to inspect a process’s loaded modules:
File Formats: PE and ELF¶
Executable files (e.g., malware) are structured using formats like PE (Windows) or ELF (Linux). These formats define how code and data are organized.
PE (Portable Executable):
- Header: Metadata (entry point, sections).
- Sections: Code (.text), data (.data), resources (.rsrc).
- Import/Export tables: References to external libraries.
ELF (Executable and Linkable Format):
- Header: File type (executable, shared library).
- Sections: Similar to PE, but with additional segments for memory mapping.
- Program headers: Define how the file is loaded into memory.
Example: Analyze a PE file with Ghidra:
Static vs Dynamic Analysis¶
Static analysis examines code without execution, while dynamic analysis observes behavior in runtime. Both are complementary in reverse engineering.
Static Analysis:
- Tools: Disassemblers (Ghidra), decompilers.
- Advantages: No need for execution, reveals code structure.
- Limitations: Cannot detect runtime-dependent behavior (e.g., API calls, encryption).
Dynamic Analysis:
- Tools: Debuggers (Ghidra’s debugger plugin), sandboxes.
- Advantages: Captures runtime data (registers, memory, network traffic).
- Limitations: May miss obfuscated logic or require controlled environments.
Example: Combine both approaches:
# Ghidra static analysis
ghidraRun -open /path/to/malware.exe -script analyze_static.py
# Ghidra dynamic analysis (debugger)
ghidraRun -open /path/to/malware.exe -debugger
Key takeaways¶
- Memory analysis reveals how malware operates in runtime environments.
- PE/ELF formats provide structural insights into executable behavior.
- Static analysis is ideal for code structure, while dynamic analysis captures runtime interactions.
- Tools like Ghidra integrate both methods to enable comprehensive reverse engineering.