首页> 外文期刊>Journal of Computer Virology and Hacking Techniques >A similarity metric method of obfuscated malware using function-call graph
【24h】

A similarity metric method of obfuscated malware using function-call graph

机译:使用函数调用图的模糊恶意软件相似度度量方法

获取原文
获取原文并翻译 | 示例
           

摘要

Code obfuscating technique plays a significant role to produce new obfuscated malicious programs, generally called malware variants, from previously encountered malwares. However, the traditional signature-based malware detecting method is hard to recognize the up-to-the-minute obfuscated malwares. This paper proposes a method to identify the malware variants based on the function-call graph. Firstly, the function-call graphs were created from the disassembled codes of program; then the caller–callee relationships of functions and the operational code (opcode) information about functions, combining the graph coloring techniques were used to measure the similarity metric between two function-call graphs; at last, the similarity metric was utilized to identify the malware variants from known malwares. The experimental results show that the proposed method is able to identify the obfuscated malicious softwares effectively.
机译:代码混淆技术在从先前遇到的恶意软件中产生新的混淆的恶意程序(通常称为恶意软件变体)方面发挥着重要作用。但是,传统的基于签名的恶意软件检测方法很难识别最新的混淆软件。本文提出了一种基于功能调用图的恶意软件变种识别方法。首先,从反汇编的程序代码创建函数调用图;然后使用函数的调用者与被调用者之间的关系以及有关函数的操作代码(操作码)信息,结合图着色技术来测量两个函数调用图之间的相似性度量;最后,利用相似性度量从已知恶意软件中识别出恶意软件变体。实验结果表明,该方法能够有效识别被混淆的恶意软件。

著录项

  • 来源
  • 作者单位

    College of Computer Hangzhou Dianzi University">(1);

    College of Computer Hangzhou Dianzi University">(1);

    College of Computer Hangzhou Dianzi University">(1);

    College of Computer Hangzhou Dianzi University">(1);

    College of Computer Hangzhou Dianzi University">(1);

    College of Computer Hangzhou Dianzi University">(1);

    College of Computer Hangzhou Dianzi University">(1);

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号