EDBT 2026 Demo / reviewers in the wild / expert
Fabrice Sabatier
dblp:78/3545
· DBLP profile ↗
1ranked-venue papers
0as first author
0since 2021 · last 2015
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 67% Malware analysis · 33% |
Topics — the 3 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › binary analysis
disassembly |
0.2 | 1 | 2015 | CoDisasm: Medium Scale Concatic Disassembly of Self-Modifying Binaries with Overlapping Instructions · CCS 2015 |
Malware analysis
obfuscation analysis |
0.2 | 1 | 2015 | CoDisasm: Medium Scale Concatic Disassembly of Self-Modifying Binaries with Overlapping Instructions · CCS 2015 |
Systems and software security
self-modifying code |
0.2 | 1 | 2015 | CoDisasm: Medium Scale Concatic Disassembly of Self-Modifying Binaries with Overlapping Instructions · CCS 2015 |
Methods — techniques the papers use, named apart from their topics
static disassembly · 0.2concrete path execution · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2015 | CoDisasm: Medium Scale Concatic Disassembly of Self-Modifying Binaries with Overlapping InstructionsabstractFighting malware involves analyzing large numbers of suspicious binary files. In this context, disassembly is a crucial task in malware analysis and reverse engineering. It involves the recovery of assembly instructions from binary machine code. Correct disassembly of binaries is necessary to produce a higher level representation of the code and thus allow the analysis to develop high-level understanding of its behavior and purpose. Nonetheless, it can be problematic in the case of malicious code, as malware writers often employ techniques to thwart correct disassembly by standard tools. In this paper, we focus on the disassembly of x86 self-modifying binaries with overlapping instructions. Current state-of-the-art disassemblers fail to interpret these two common forms of obfuscation, causing an incorrect disassembly of large parts of the input. We introduce a novel disassembly method, called concatic disassembly, that combines CONCrete path execution with stATIC disassembly. We have developed a standalone disassembler called CoDisasm that implements this approach. Guillaume Bonfante, José M. Fernandez 0001, Jean-Yves Marion, Benjamin Rouxel, Fabrice Sabatier, Aurélien Thierry |
CCS | 5 |