首页> 外文会议>2011 IEEE International Carnahan Conference on Security Technology >A concept for monitoring self-transforming code using memory page access control management
【24h】

A concept for monitoring self-transforming code using memory page access control management

机译:使用内存页面访问控制管理监视自转换代码的概念

获取原文

摘要

Current antivirus software still focuses on using signature based algorithms on file content level to detect malware. Unfortunately, there is a simple way to circumvent this detection method: The malware author applies a code transformation algorithm (e.g. a packing or encryption scheme) to his malware plaintext and saves the reverse transformation algorithm along with the unsuspicious looking block of transformed mal-ware. Malware, which is obfuscated in that way, is called polymorphic malware. We call the transformation of the plaintext to the transformed malware as encoding and the reverse operation as decoding. Although current malware detection systems adopted and implemented several techniques to counter this, these methods are mostly either unreliable or suffer heavy performance drawbacks. We present a non-intrusive and lightweight method to monitor any executable code in real-time, which allows efficient detection of polymorphic malware.
机译:当前的防病毒软件仍专注于在文件内容级别使用基于签名的算法来检测恶意软件。不幸的是,有一种简单的方法可以避免这种检测方法:恶意软件作者将代码转换算法(例如打包或加密方案)应用于他的恶意软件明文,并保存反向转换算法以及看起来毫无疑问的转换恶意软件块。以这种方式进行混淆的恶意软件称为多态恶意软件。我们将纯文本转换为转换后的恶意软件称为编码,将反向操作称为解码。尽管当前的恶意软件检测系统采用并实施了多种技术来解决此问题,但是这些方法大多不可靠或存在严重的性能缺陷。我们提出了一种非侵入性的轻量级方法来实时监视任何可执行代码,从而可以有效地检测多态恶意软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号