{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2022:AUXX3TA4MQNERBM65GASVY6BCE","short_pith_number":"pith:AUXX3TA4","canonical_record":{"source":{"id":"2212.04008","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-12-07T23:51:42Z","cross_cats_sorted":[],"title_canon_sha256":"7330fa1b6adf83a4966244737336ab0d6b8f1d569b4fd4b3d2b12c18b52dbc9e","abstract_canon_sha256":"b1af1bd48fb97e7e7127abdb203c9e960d8d4ab40da43a26fc5351948a6f9f00"},"schema_version":"1.0"},"canonical_sha256":"052f7dcc1c641a48859ee9812ae3c11125c175a1c5c65dd4d19b43f36814ad62","source":{"kind":"arxiv","id":"2212.04008","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2212.04008","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"arxiv_version","alias_value":"2212.04008v3","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2212.04008","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"pith_short_12","alias_value":"AUXX3TA4MQNE","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"pith_short_16","alias_value":"AUXX3TA4MQNERBM6","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"pith_short_8","alias_value":"AUXX3TA4","created_at":"2026-07-05T06:48:46Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2022:AUXX3TA4MQNERBM65GASVY6BCE","target":"record","payload":{"canonical_record":{"source":{"id":"2212.04008","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-12-07T23:51:42Z","cross_cats_sorted":[],"title_canon_sha256":"7330fa1b6adf83a4966244737336ab0d6b8f1d569b4fd4b3d2b12c18b52dbc9e","abstract_canon_sha256":"b1af1bd48fb97e7e7127abdb203c9e960d8d4ab40da43a26fc5351948a6f9f00"},"schema_version":"1.0"},"canonical_sha256":"052f7dcc1c641a48859ee9812ae3c11125c175a1c5c65dd4d19b43f36814ad62","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:48:46.339955Z","signature_b64":"Q0qFAIBKgD+i6b9JPyrvlDS1cnCJRZYQuyYi8ncZ1q7O2LX8DFasWDDaESAJL/2Z6831ZD+0sYVZs7YcElh9BQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"052f7dcc1c641a48859ee9812ae3c11125c175a1c5c65dd4d19b43f36814ad62","last_reissued_at":"2026-07-05T06:48:46.339381Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:48:46.339381Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2212.04008","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T06:48:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"vSIUhI5a/SBwz9WDw73Nuh/nIH2mHVPI8OWThyz4O7kFRzbO+bAucG00KivYD9BmcKwHMhYAZc6CZI3907X3AA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-12T14:08:00.221116Z"},"content_sha256":"81ec8ed71461ca135d99e778c9ca310f33f2a5fae1bc078e0bb0d337cc49b1a7","schema_version":"1.0","event_id":"sha256:81ec8ed71461ca135d99e778c9ca310f33f2a5fae1bc078e0bb0d337cc49b1a7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2022:AUXX3TA4MQNERBM65GASVY6BCE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Use of Cryptography in Malware Obfuscation","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Benjamin Zi Hao Zhao, Dali Kaafar, Daniel Coscia, Giang Nguyen, Hassan Jameel Asghar, Muhammad Ikram, Sean Lamont","submitted_at":"2022-12-07T23:51:42Z","abstract_excerpt":"Malware authors often use cryptographic tools such as XOR encryption and block ciphers like AES to obfuscate part of the malware to evade detection. Use of cryptography may give the impression that these obfuscation techniques have some provable guarantees of success. In this paper, we take a closer look at the use of cryptographic tools to obfuscate malware. We first find that most techniques are easy to defeat (in principle), since the decryption algorithm and the key is shipped within the program. In order to clearly define an obfuscation technique's potential to evade detection we propose "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2212.04008","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2212.04008/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T06:48:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"K6SHdehQZ2lUXhJVhTvWU+zU32sIVNhGsDlVkgR5bvHIAdHMwnAB7CvQWu+JRxYSXEGwhLyglkuXqwaF15r6Dw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-12T14:08:00.221917Z"},"content_sha256":"81049ce5b15079f516009b9cdec9e4a98de7109fc37341851efbccdd7bd0b723","schema_version":"1.0","event_id":"sha256:81049ce5b15079f516009b9cdec9e4a98de7109fc37341851efbccdd7bd0b723"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/AUXX3TA4MQNERBM65GASVY6BCE/bundle.json","state_url":"https://pith.science/pith/AUXX3TA4MQNERBM65GASVY6BCE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/AUXX3TA4MQNERBM65GASVY6BCE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-12T14:08:00Z","links":{"resolver":"https://pith.science/pith/AUXX3TA4MQNERBM65GASVY6BCE","bundle":"https://pith.science/pith/AUXX3TA4MQNERBM65GASVY6BCE/bundle.json","state":"https://pith.science/pith/AUXX3TA4MQNERBM65GASVY6BCE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/AUXX3TA4MQNERBM65GASVY6BCE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2022:AUXX3TA4MQNERBM65GASVY6BCE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b1af1bd48fb97e7e7127abdb203c9e960d8d4ab40da43a26fc5351948a6f9f00","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-12-07T23:51:42Z","title_canon_sha256":"7330fa1b6adf83a4966244737336ab0d6b8f1d569b4fd4b3d2b12c18b52dbc9e"},"schema_version":"1.0","source":{"id":"2212.04008","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2212.04008","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"arxiv_version","alias_value":"2212.04008v3","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2212.04008","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"pith_short_12","alias_value":"AUXX3TA4MQNE","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"pith_short_16","alias_value":"AUXX3TA4MQNERBM6","created_at":"2026-07-05T06:48:46Z"},{"alias_kind":"pith_short_8","alias_value":"AUXX3TA4","created_at":"2026-07-05T06:48:46Z"}],"graph_snapshots":[{"event_id":"sha256:81049ce5b15079f516009b9cdec9e4a98de7109fc37341851efbccdd7bd0b723","target":"graph","created_at":"2026-07-05T06:48:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2212.04008/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Malware authors often use cryptographic tools such as XOR encryption and block ciphers like AES to obfuscate part of the malware to evade detection. Use of cryptography may give the impression that these obfuscation techniques have some provable guarantees of success. In this paper, we take a closer look at the use of cryptographic tools to obfuscate malware. We first find that most techniques are easy to defeat (in principle), since the decryption algorithm and the key is shipped within the program. In order to clearly define an obfuscation technique's potential to evade detection we propose ","authors_text":"Benjamin Zi Hao Zhao, Dali Kaafar, Daniel Coscia, Giang Nguyen, Hassan Jameel Asghar, Muhammad Ikram, Sean Lamont","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-12-07T23:51:42Z","title":"Use of Cryptography in Malware Obfuscation"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2212.04008","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:81ec8ed71461ca135d99e778c9ca310f33f2a5fae1bc078e0bb0d337cc49b1a7","target":"record","created_at":"2026-07-05T06:48:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b1af1bd48fb97e7e7127abdb203c9e960d8d4ab40da43a26fc5351948a6f9f00","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-12-07T23:51:42Z","title_canon_sha256":"7330fa1b6adf83a4966244737336ab0d6b8f1d569b4fd4b3d2b12c18b52dbc9e"},"schema_version":"1.0","source":{"id":"2212.04008","kind":"arxiv","version":3}},"canonical_sha256":"052f7dcc1c641a48859ee9812ae3c11125c175a1c5c65dd4d19b43f36814ad62","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"052f7dcc1c641a48859ee9812ae3c11125c175a1c5c65dd4d19b43f36814ad62","first_computed_at":"2026-07-05T06:48:46.339381Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T06:48:46.339381Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Q0qFAIBKgD+i6b9JPyrvlDS1cnCJRZYQuyYi8ncZ1q7O2LX8DFasWDDaESAJL/2Z6831ZD+0sYVZs7YcElh9BQ==","signature_status":"signed_v1","signed_at":"2026-07-05T06:48:46.339955Z","signed_message":"canonical_sha256_bytes"},"source_id":"2212.04008","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:81ec8ed71461ca135d99e778c9ca310f33f2a5fae1bc078e0bb0d337cc49b1a7","sha256:81049ce5b15079f516009b9cdec9e4a98de7109fc37341851efbccdd7bd0b723"],"state_sha256":"9658b438f35b51bc3066961b49f247e661899ba3f2eb01a80e8f9de725196819"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yX+x4A3WSfq7WR+Nwy1wJ3C6cCpCBYLrbnk6o2BIQv2MbMRhpLevL+sNR+z2rYgFHEu2YOECo+pW6irJfDCmAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-12T14:08:00.227325Z","bundle_sha256":"a81a2347c962c83ac2b167f7907bb00d3fb4db5f7f9032a5bf9c4067f86c4193"}}