首页> 外文会议>International Conference on Cyberspace Technology >A parallel target-directed analysis method for malware behaviors
【24h】

A parallel target-directed analysis method for malware behaviors

机译:针对恶意软件行为的并行目标导向分析方法

获取原文

摘要

To improve the efficiency of analyzing malware behaviors and increase the validity of the test data, this paper proposes a parallel target-directed analysis method for malware behaviors, which combines static analysis with concolic testing techniques. It first uses static analysis techniques to identify and locate those interactive or input points and sensitive behavior functions. Then based on the distributed platform, by combining symbolic execution and concrete dynamic execution together and taking malware sensitive behaviors as the leading target, the parallel target-directed algorithm of searching sensitive paths and the method of leading and approaching sensitive behaviors are designed. It leads to traverse the sensitive functions, obtain the sensitive paths which can reach the sensitive behavior areas by path backtracking, and generate the corresponding test data. Finally, it finishes the analysis and test of malware behaviors. Experiments show that, compared with fuzz and full paths covering and traversing technique, this method can generate test data more efficiently, reduce the number of paths to be analyzed, and improve the analysis speed and efficiency of malware behaviors.
机译:为了提高恶意软件行为的分析效率并提高测试数据的有效性,本文提出了一种针对目标的并行恶意软件行为分析方法,该方法将静态分析与Concilly测试技术相结合。它首先使用静态分析技术来识别和定位那些交互式或输入点以及敏感行为功能。然后,在分布式平台的基础上,将符号执行与具体动态执行结合起来,以恶意软件敏感行为为主导目标,设计了并行目标导向的敏感路径搜索算法以及敏感行为的引导与处理方法。它导致遍历敏感功能,通过路径回溯获得可以到达敏感行为区域的敏感路径,并生成相应的测试数据。最后,它完成了对恶意软件行为的分析和测试。实验表明,与模糊和全路径覆盖和遍历技术相比,该方法可以更有效地生成测试数据,减少要分析的路径数量,并提高恶意软件行为的分析速度和效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号