...
首页> 外文期刊>Journal of Computers >A Bit Vector Based Binary Code Comparison Method for Static Malware Analysis
【24h】

A Bit Vector Based Binary Code Comparison Method for Static Malware Analysis

机译:基于比特向量的二进制代码比较方法,用于静态恶意软件分析

获取原文
           

摘要

As variants of malicious codes have made it difficult and complicated to detect possible threat inthe Internet, it is one of the most important challenges to analyze the malwares correctly in a timely manner.It has been also observed that we need static analysis as well as dynamic analysis to detect the malwarecorrectly. In this paper, we define a bit vector to characterize a binary code, and utilize it for static malwareanalysis. Since each bit of a bit vector is organized to indicate the existence of a certain function or codeblock, we could replace a comparison operation on binary codes by simple logical operations. Commonfeatures of a group of binary codes could be also captured by bit vectors, which would be used to determinewhether another binary code is similar to those of the group or not. Experimental results show that the bitvector could be effectively utilized to do static malware analysis, and that the group bit vectors could helpclassify the malwares into their appropriate groups.
机译:由于恶意代码的变种使得检测可能的威胁难以互联网,它是以及时的方式正确分析恶意的最重要挑战之一。已经观察到我们需要静态分析以及动态分析检测棕褐色。在本文中,我们定义了一个位矢量,以表征二进制代码,并利用它用于静态恶意分析。由于组织了比特向量的每个位以指示某个函数或码块的存在,因此我们可以通过简单的逻辑运算替换对二进制代码的比较操作。可以通过位向量捕获一组二进制代码的共同规范,该比特向量将用于确定另一个二进制代码与本组的比特码类似。实验结果表明,可以有效地利用该位VERCORE来进行静态恶意软件分析,并且群体比特向量可以帮助恶意释放态度进入适当的群体。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号