首页> 外文会议>2011 IEEE International Carnahan Conference on Security Technology >A theoretical implementation of Blended Program Analysis for virus signature extraction
【24h】

A theoretical implementation of Blended Program Analysis for virus signature extraction

机译:用于病毒签名提取的混合程序分析的理论实现

获取原文

摘要

Usually, two methods are used in order to detect a virus viz. Signature detection and Anomaly detection. In this paper, we''ll talk about the signature extraction process. Virus signatures can be extracted by analyzing the virus in a safe environment usually provided by a sandbox or a virtual machine. We can define the virus analysis as “the action of taking virus apart in order to study it”. The analysis is done by implementing the methods of program analysis. Traditionally, there were two methods of program analysis viz. Static Program Analysis and Dynamic Program Analysis. Recently, a new method has been invented called Blended Program Analysis. This method combines a dynamic representation of the program calling structure, with a static analysis applied to a region of that calling structure with observed performance problems. In the malware''s perspective, a performance problem can be substituted with activities like registry editing or other such activities that result into a system failure. In this paper, we''ll explore the possibilities of extracting the signatures of viruses, including complex viruses such as macro viruses, by making use of Blended Program Analysis. Since, this paper is a theoretical study we won''t be dealing with any kind of experiments or experimental data.
机译:通常,为了检测病毒即使用两种方法。签名检测和异常检测。在本文中,我们将讨论签名提取过程。可以通过在通常由沙箱或虚拟机提供的安全环境中分析病毒来提取病毒签名。我们可以将病毒分析定义为“将病毒拆散以进行研究的动作”。通过执行程序分析方法来完成分析。传统上,有两种程序分析方法,即。静态程序分析和动态程序分析。最近,发明了一种称为混合程序分析的新方法。该方法将程序调用结构的动态表示与对观察到的性能问题应用于该调用结构的区域的静态分析相结合。从恶意软件的角度来看,可以用注册表编辑之类的活动或其他导致系统故障的活动来代替性能问题。在本文中,我们将探索通过使用混合程序分析来提取病毒签名(包括复杂病毒,例如宏病毒)的可能性。由于本文是一项理论研究,因此我们将不涉及任何种类的实验或实验数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号