{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:39:31Z","timestamp":1783438771014,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":65,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100019062","name":"Tianjin Research Innovation Project for Postgraduate Students","doi-asserted-by":"publisher","award":["2019YJSS092"],"award-info":[{"award-number":["2019YJSS092"]}],"id":[{"id":"10.13039\/501100019062","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172238, 61972215, and 61972073"],"award-info":[{"award-number":["62172238, 61972215, and 61972073"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key R&D Program of China","award":["2018YFA0704703"],"award-info":[{"award-number":["2018YFA0704703"]}]},{"name":"Natural Science Foundation of Tianjin","award":["20JCZDJC00640"],"award-info":[{"award-number":["20JCZDJC00640"]}]},{"name":"National Science Foundation (NSF)","award":["CNS-2128703"],"award-info":[{"award-number":["CNS-2128703"]}]},{"name":"Carol Lavin Bernick Faculty Grant"},{"name":"Fundamental Research Funds for the Central Universities of China"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3616625","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"3078-3092","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["PackGenome: Automatically Generating Robust YARA Rules for Accurate Malware Packer Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3527-1332","authenticated-orcid":false,"given":"Shijia","family":"Li","sequence":"first","affiliation":[{"name":"Nankai University, TKLNDST, &amp; DISSEC, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9682-0502","authenticated-orcid":false,"given":"Jiang","family":"Ming","sequence":"additional","affiliation":[{"name":"Tulane University, New Orleans, LA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-4073-1649","authenticated-orcid":false,"given":"Pengda","family":"Qiu","sequence":"additional","affiliation":[{"name":"Nankai University, TKLNDST, &amp; DISSEC, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7165-2800","authenticated-orcid":false,"given":"Qiyuan","family":"Chen","sequence":"additional","affiliation":[{"name":"Nankai University, TKLNDST, &amp; DISSEC, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-7838-7101","authenticated-orcid":false,"given":"Lanqing","family":"Liu","sequence":"additional","affiliation":[{"name":"Nankai University, TKLNDST, &amp; DISSEC, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9657-3633","authenticated-orcid":false,"given":"Huaifeng","family":"Bao","sequence":"additional","affiliation":[{"name":"SKLOIS, IIE, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1115-2387","authenticated-orcid":false,"given":"Qiang","family":"Wang","sequence":"additional","affiliation":[{"name":"SKLOIS, IIE, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5588-9690","authenticated-orcid":false,"given":"Chunfu","family":"Jia","sequence":"additional","affiliation":[{"name":"Nankai University, TKLNDST, &amp; DISSEC, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"ACM Computing Surveys (CSUR)","volume":"55","author":"Muralidharan Trivikram","year":"2022","unstructured":"Trivikram Muralidharan, Aviad Cohen, Noa Gerson, and Nir Nissim. 2022. File Packing from the Malware Perspective: Techniques, Analysis Approaches, and Directions for Enhancements. ACM Computing Surveys (CSUR), Vol. 55 (April 2022), 1--45."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2522968.2522972"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484759"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 36th IEEE Symposium on Security and Privacy (S&P). IEEE, 659--673","author":"Ugarte-Pedrero Xabier","unstructured":"Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, and Pablo G. Bringas. 2015. SoK: Deep Packer Inspection: A Longitudinal Study of the Complexity of Run-Time Packers. In Proceedings of the 36th IEEE Symposium on Security and Privacy (S&P). IEEE, 659--673."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.19"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24310"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053002"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_4"},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security). USENIX Association, 3451--3468","author":"Cheng Binlin","year":"2021","unstructured":"Binlin Cheng, Jiang Ming, Erika A. Leal, Haotian Zhang, Jianming Fu, Guojun Peng, and Jean Yves Marion. 2021. Obfuscation-Resilient Executable Payload Extraction From Packed Malware. In Proceedings of the 30th USENIX Security Symposium (USENIX Security). USENIX Association, 3451--3468."},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security). USENIX Association, 3487--3504","author":"Avllazagaj Erin","year":"2021","unstructured":"Erin Avllazagaj, Ziyun Zhu, Leyla Bilge, Davide Balzarotti, and Tudor Dumitras. 2021. When Malware Changed Its Mind: An Empirical Study of Variable Program Behaviors in the Real World. In Proceedings of the 30th USENIX Security Symposium (USENIX Security). USENIX Association, 3487--3504."},{"key":"e_1_3_2_1_11_1","unstructured":"VirusTotal. VirusTotal - Stats. https:\/\/www.virustotal.com\/gui\/stats (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_12_1","unstructured":"Victor Manuel Alvarez. YARA - The Pattern Matching Swiss Knife for Malware Researchers. https:\/\/virustotal.github.io\/yara\/ (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_13_1","unstructured":"Horsicq. Detect-It-Easy. https:\/\/github.com\/horsicq\/Detect-It-Easy (accessed on 2022--12-07)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00054"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.48"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2010.5665789"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.3390\/e19030125"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24297"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.05.007"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427273"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-61078-4_3"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3411508.3421372"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2022.103267"},{"key":"e_1_3_2_1_24_1","unstructured":"Aldeid. PEiD. https:\/\/www.aldeid.com\/wiki\/PEiD (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security). USENIX Association, 3469--3486","author":"Downing Evan","year":"2021","unstructured":"Evan Downing, Yisroel Mirsky, Kyuhong Park, and Wenke Lee. 2021. DeepReflect: Discovering Malicious Functionality through Binary Reconstruction. In Proceedings of the 30th USENIX Security Symposium (USENIX Security). USENIX Association, 3469--3486."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3457894"},{"key":"e_1_3_2_1_27_1","unstructured":"Unipacker. Unpacking PE files using Unicorn Engine. https:\/\/github.com\/uniPacker\/uniPacker (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security). USENIX Association","author":"Votipka Daniel","unstructured":"Daniel Votipka, Seth M. Rabin, Kristopher Micinski, Jeffrey S. Foster, and Michelle M. Mazurek. 2020. An Observational Investigation of Reverse Engineers' Processes. In Proceedings of the 29th USENIX Security Symposium (USENIX Security). USENIX Association, 1875--1892."},{"key":"e_1_3_2_1_29_1","unstructured":"Oreans Technologies. Themida Overview. https:\/\/www.oreans.com\/themida.php (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87403-4_6"},{"key":"e_1_3_2_1_31_1","unstructured":"Dhondta. Awesome Executable Packing. https:\/\/github.com\/dhondta\/awesome-executable-packing (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_32_1","unstructured":"Ange Albertini. Packers. https:\/\/corkami.blogspot.com\/ (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_33_1","unstructured":"Rufus Brown Van Ta Douglas Bienstock Geoff Ackerman and John Wolfram. Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. https:\/\/www.mandiant.com\/resources\/apt41-us-state-governments (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_34_1","unstructured":"Cisco Talos Intelligence Group. New Research Paper: Prevalence and impact of low-entropy packing schemes in the malware ecosystem. https:\/\/blog.talosintelligence.com\/2020\/02\/new-research-paper-prevalence-and.html (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_35_1","unstructured":"Intel. Intel\u00ae 64 and IA-32 Architectures Software Developer Manuals. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-sdm.html (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1101\/gr.3737405"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2908080.2908126"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243771"},{"key":"e_1_3_2_1_39_1","unstructured":"Arne Swinnen and Alaeddine Mesbahi. 2014. One Packer to Rule them All: Empirical Identification Comparison and Circumvention of Current Antivirus Detection Techniques. In BlackHat USA. BlackHat 1--55."},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the 25th Annual Network and Distributed System Security Symposium (NDSS). Internet Society.","author":"Bauman Erick","unstructured":"Erick Bauman, Zhiqiang Lin, and Kevin W. Hamlen. 2018. Superset Disassembly: Statically Rewriting x86 Binaries Without Heuristics. In Proceedings of the 25th Annual Network and Distributed System Security Symposium (NDSS). Internet Society."},{"key":"e_1_3_2_1_41_1","volume-title":"REcon","author":"Pericin Tomislav","year":"2011","unstructured":"Tomislav Pericin. 2011. Reversing software compressions: Tale of dragons and men who slay them. In REcon 2011. REcon."},{"key":"e_1_3_2_1_42_1","unstructured":"the MITRE Corporation. Obfuscated Files or Information: Software Packing. https:\/\/attack.mitre.org\/techniques\/T1027\/002\/ (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_43_1","unstructured":"Thomas Barabosch. The malware analyst's guide to aPLib decompression. https:\/\/0xc0decafe.com\/malware-analysts-guide-to-aplib-decompression (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_44_1","unstructured":"Microsoft. PE Format. https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/debug\/pe-format (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_45_1","unstructured":"Yara-rules. rules. https:\/\/github.com\/Yara-Rules\/rules (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_46_1","unstructured":"Avast. retdec. https:\/\/github.com\/avast\/retdec\/tree\/master\/support\/yara_patterns\/tools (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_47_1","unstructured":"JusticeRage. Manalyze. https:\/\/github.com\/JusticeRage\/Manalyze (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_48_1","unstructured":"Godaddy. yara-rules. https:\/\/github.com\/godaddy\/yara-rules\/ (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_49_1","unstructured":"AlienVault-OTX. OTX-Python-SDK. https:\/\/github.com\/AlienVault-OTX\/OTX-Python-SDK (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_50_1","unstructured":"X64dbg. yarasigs. https:\/\/github.com\/x64dbg\/yarasigs (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_51_1","unstructured":"Xen0ph0n. YaraGenerator. https:\/\/github.com\/Xen0ph0n\/YaraGenerator (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_52_1","unstructured":"AlienVault-OTX. yabin. https:\/\/github.com\/AlienVault-OTX\/yabin (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_53_1","unstructured":"Neo23x0. yarGen. https:\/\/github.com\/Neo23x0\/yarGen (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24015"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813663"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065034"},{"key":"e_1_3_2_1_57_1","volume-title":"Proceedings of the 2013 USENIX Annual Technical Conference (USENIX ATC). USENIX Association, 187--198","author":"Hu Xin","year":"2013","unstructured":"Xin Hu, Kang G Shin, Sandeep Bhatkar, and Kent Griffin. 2013. MutantX-S: Scalable Malware Clustering Based on Static Features. In Proceedings of the 2013 USENIX Annual Technical Conference (USENIX ATC). USENIX Association, 187--198."},{"key":"e_1_3_2_1_58_1","unstructured":"A.S.L. EXEINFO PE. http:\/\/www.exeinfo.byethost18.com (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_59_1","unstructured":"Vx-underground team. vx-underground. https:\/\/samples.vx-underground.org\/ (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_60_1","unstructured":"Cyber-research. APTMalware. https:\/\/github.com\/cyber-research\/APTMalware (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_61_1","unstructured":"MalwareSamples. Linux-Malware-Samples. https:\/\/github.com\/MalwareSamples\/Linux-Malware-Samples (accessed on 2022-12-09)."},{"key":"e_1_3_2_1_62_1","unstructured":"Horsicq. Fix: 2022-06-02 \u00b7 horsicq\/Detect-It-Easy@c332fa4 \u00b7 GitHub. https:\/\/github.com\/horsicq\/Detect-It-Easy\/commit\/c332fa452087bc0e6705c452e00331618a9da00e (accessed on 2022--12-09)."},{"key":"e_1_3_2_1_63_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security). USENIX Association, 3541--3558","author":"Brengel Michael","year":"2021","unstructured":"Michael Brengel and Christian Rossow. 2021. YARIX: Scalable YARA-based Malware Intelligence. Proceedings of the 30th USENIX Security Symposium (USENIX Security). USENIX Association, 3541--3558."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813627"},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of the 32nd USENIX Security Symposium (USENIX Security). USENIX Association, 7481--7498","author":"Cheng Binlin","year":"2023","unstructured":"Binlin Cheng, Erika A. Leal, Haotian Zhang, and Jiang Ming. 2023. On the Feasibility of Malware Unpacking via Hardware-assisted Loop Profiling. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security). USENIX Association, 7481--7498."}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616625","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3616625","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:50:17Z","timestamp":1755741017000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616625"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":65,"alternative-id":["10.1145\/3576915.3616625","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3616625","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}