【24h】

The use of static analysis to detect malware in embedded systems

机译:使用静态分析来检测嵌入式系统中的恶意软件

获取原文
获取原文并翻译 | 示例

摘要

Malware is prolific and not always detected until the damage has occurred. The use of Formal Static Analysis techniques to ensure that software-based safety systems are free from compiler introduced errors is well established (Pavey, Winsborrow, 1995) [1]. This technique ensures that the executable binary code created by the compiler is mathematically equivalent to the original source code. This paper reports on extending this technique to detect malware inserted into executable code. The Source-Code Comparison process was originally developed by British Energy for the verification of the Primary Reactor Protection System software of the Sizewell `B' Nuclear Power Plant. The process takes the executable binary file that is resident on the target computer and re-creates the equivalent assembler code using disassembler tools. This is then formally compared to the original source code using the MALPAS Compliance Analysis tool, and any discrepancies are revealed. The process has the ability to detect any executable binary code that cannot be traced back to the source code, and may therefore be used to detect the presence of malware in the executable. The paper reports on experiments conducted by Atkins to determine whether modern control executable software can be formally proven against the original code. The applicability of the process to software developed for general purpose operating systems (e.g. Windows) will also be evaluated.
机译:恶意软件是多产的,只有在损坏发生之前才能被发现。使用形式静态分析技术来确保基于软件的安全系统不受编译器引入的错误的影响已经确立(Pavey,Winsborrow,1995)[1]。此技术可确保由编译器创建的可执行二进制代码在数学上等效于原始源代码。本文报告了有关扩展该技术以检测插入到可执行代码中的恶意软件的信息。源代码比较过程最初是由英国能源公司开发的,用于验证Sizewell'B'核电厂的一次反应堆保护系统软件。该过程将获取驻留在目标计算机上的可执行二进制文件,然后使用反汇编程序工具重新创建等效的汇编程序代码。然后使用MALPAS符合性分析工具将其与原始源代码进行正式比较,并发现任何差异。该过程具有检测任何无法追溯到源代码的可执行二进制代码的能力,因此可以用于检测可执行文件中是否存在恶意软件。该论文报告了由阿特金斯(Atkins)进行的实验,以确定是否可以对照原始代码正式证明现代控制可执行软件。还将评估该过程对为通用操作系统(例如Windows)开发的软件的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号