【24h】

Approach for the unknown metamorphic virus detection

机译:未知变态病毒检测方法

获取原文

摘要

The paper presents a new technique for unknown metamorphic viruses' detection. It is based on the analysis of the potentially suspicious behavior of the programs on the host. The novelty of the contribution is that, the analysis is performed via the comparison of the functional blocks of the disassembled code before and after program's emulation, which is executed within the modified emulators installed on each host of the network. The conclusion about the similarity of the suspicious program to the metamorphic virus program is performed by the means of the fuzzy inference system. In order to provoke possible presence of the metamorphic virus other hosts of the network are involved in the detection process. Thus, experimentally it was shown that level of metamorphic viruses' demonstration increases with the number of hosts.
机译:本文提出了一种检测未知变态病毒的新技术。它基于对主机上程序的潜在可疑行为的分析。贡献的新颖之处在于,通过在程序仿真之前和之后对反汇编代码的功能块进行比较来执行分析,该比较是在安装在网络每个主机上的修改后的仿真器中执行的。利用模糊推理系统对可疑程序与变态病毒程序的相似性进行了结论。为了激发变态病毒的可能存在,网络的其他主机也参与了检测过程。因此,实验表明,变态病毒的展示水平随宿主数量的增加而增加。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号