首页> 外文会议>International Conference on Information and Network Security >Search algorithm based on priority in semantic method for malicious code detection
【24h】

Search algorithm based on priority in semantic method for malicious code detection

机译:基于优先级的恶意代码检测的优先级的搜索算法

获取原文

摘要

This paper present a search algorithm based on priority to detect malicious behavior in the semantic method with respect to morph technology in computer viruses. For Win32 PE virus, use disassembly technologies to get the assembly code of the program, and then establish the program flow chart with help of the intermediate representation. Next, match the malicious behavior template with the program flow chart. Search algorithm based on priority is used to find def-use relationship for detecting malicious behavior. The experiment results show that the search algorithm is fast and effective for invalid code insertion, code transposition, and register reassignment and partially effective for instruction substitution.
机译:本文介绍了一种基于优先级的搜索算法,以检测语义方法中的恶意行为在计算机病毒中的变形技术。 对于Win32 PE病毒,请使用拆卸技术获取程序的汇编代码,然后在中间表示的帮助下建立程序流程图。 接下来,将恶意行为模板与程序流程图匹配。 基于优先级的搜索算法用于查找用于检测恶意行为的Def-Imperify关系。 实验结果表明,搜索算法对于无效的代码插入,代码转换和注册重新分配以及用于指令替换的部分有效的搜索算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号